Page 1 of 1

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Posted: Fri Sep 18, 2026 5:13 am
by Starburst-David
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.

An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.

Full article at:
https://thehackernews.com/2026/09/criti ... -flaw.html

Published Date: Sep 17, 2026

Vulnerabilities has been mentioned in this article:
CVE-2026-85501 CVE-2026-82720 CVE-2026-82717 CVE-2026-81642 CVE-2026-81634 CVE-2026-80225 CVE-2026-78227 CVE-2026-77955 CVE-2026-77860 CVE-2026-33278