BIND DNS Servers Receive Patches for 14 Vulnerabilities Including High-Severity DoS Flaws
The Internet Systems Consortium has published an update for BIND 9 that resolves 14 vulnerabilities in the world’s most widely deployed DNS server software. Seven of the flaws received a CVSS score of 7.5 and were classified as high severity, while the remaining seven scored between 5.3 and 6.5.
BIND performs the critical function of translating domain names into IP addresses. When the service stops or returns incorrect answers, the impact extends far beyond the individual server and affects every service that depends on name resolution.
The most severe issue permits an unauthenticated remote attacker to terminate the named process with a single request that carries an invalid SIG(0) signature over DNS over HTTPS. The majority of the corrected vulnerabilities do not require authentication. Several others open avenues for cache poisoning: one allows acceptance of a forged NXDOMAIN response, another downgrades secure delegation so that an unsigned answer is accepted, and a third permits out-of-zone data to be served as authoritative.
Additional problems include resource-exhaustion conditions that cause uncontrolled cache growth and excessive CPU usage, as well as integrity issues during multi-message zone transfers.
Affected versions are BIND 9.11.0 to 9.18.50, 9.20.0 to 9.20.27, and 9.21.0 to 9.21.25. Fixed releases are 9.20.29, 9.21.26, and the preview-supported 9.20.29-S1. No workarounds are available for any of the flaws. The ISC states it is not aware of any exploitation of the vulnerabilities, and none have been added to CISA’s catalog of known exploited vulnerabilities. Organizations still running the 9.18 branch are advised to plan migration to the 9.20 series.
Related articles
FBI Issues Alert on Active FortiBleed Campaign Harvesting Credentials from Exposed FortiGate Firewalls
The FBI and United States Secret Service have issued a joint alert regarding the FortiBleed campaign, an ongoing operation that targets internet-exposed FortiGate firewalls and SSL VPN gateways. Attackers have already collected 86,644 valid credentials from devices across 194 countries as of June 19, demonstrating the global scale of the indiscriminate scanning effort. The campaign relies on reused or previously leaked credentials combined with legacy SHA-256 password storage that enables offline cracking. Operators employ automated credential stuffing, the Go-based FortigateSniffer tool capable of intercepting 24 authentication protocols, and GPU-accelerated password cracking. Once inside, attackers create unauthorized administrator accounts and often delete legitimate ones, forcing victims to perform full device recovery rather than simple password resets. The activity was first documented in June, with the official alert released on October 7, confirming that scanning continues.
Cisco Patches 14 Vulnerabilities in NX-OS Software, Four Rated Critical
Cisco Systems has released security updates addressing 14 vulnerabilities in its Cisco NX-OS Software used in network devices. Four of the seven security advisories published on October 7, 2026, are rated Critical, while three are rated Medium. Several critical issues affect the Cisco Nexus 3000 Series and Nexus 9000 Series switches, impacting features such as NGOAM, MPLS OAM, and the NX-API management interface. Seven vulnerabilities received CVSSv3.1 base scores of 9.0 or higher, with multiple flaws enabling remote code execution as root or denial-of-service conditions. Specific CVEs including CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 stem from input validation failures in the NGOAM feature and may require SRv6 or NV Overlay configurations to be exploitable. The advisories also cover control plane denial-of-service issues, Python sandbox escapes, and endpoint group contract bypasses in ACI mode.
HPE Networking ClearPass Policy Manager Hit by 28 Vulnerabilities Including 10 Rated Critical
Hewlett Packard Enterprise has disclosed 28 vulnerabilities in its HPE Networking ClearPass Policy Manager product and released security updates to address them. The issues span the web management interface, APIs, endpoint agents, and client software components. Ten of the flaws received a Critical severity rating. Notable issues include SQL injection, multiple authentication bypasses, unsafe deserialization leading to remote code execution, and path traversal. No public exploit code or active discussions were observed at the time the advisory was published on October 6, 2026. The company urges customers to apply the available patches promptly.
Attackers Exploit Critical Atlassian Data Center Flaw CVE-2026-21589 Hours After PoC Release
Exploitation attempts against CVE-2026-21589 began almost immediately after technical details and a Nuclei template were published. The vulnerability allows unauthenticated arbitrary file read in multiple Atlassian Data Center products and carries a CVSS v4.0 score of 9.3. In environments integrated with Crowd, attackers who obtain crowd.properties can extract plaintext credentials and escalate to administrator privileges via the Crowd API. The flaw stems from improper handling of double-colon sequences in a shared web resource library, enabling path traversal against plugin resource endpoints. Affected products include Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian urges immediate patching outside normal cycles and recommends WAF rules or Tomcat RewriteValve configurations to block traversal patterns. Organizations should also review access logs for double-decoded URLs containing .., /, \, or :: sequences.