Unbound 1.26.1 Patches Critical DNSSEC Validator Flaw CVE-2026-81642 Enabling Remote Code Execution
NLnet Labs has released Unbound version 1.26.1 to address CVE-2026-81642, a critical flaw in its DNSSEC validator that carries risks of service disruption and potential remote code execution. The vulnerability impacts all versions through 1.26.0 and activates when the resolver processes a malicious DNS zone.
The issue lies in the DNSSEC validator during handling of DNSKEY records. Specifically, the code can experience a buffer overflow when managing data from incoming DNS responses, a scenario made more serious because the traffic arrives over the network and the process typically runs continuously.
The vendor assigned the vulnerability a CVSS 4.0 score of 9.1, with a network vector, no privileges required, and no user interaction. An attacker must control a malicious DNS zone and cause the vulnerable resolver to query it. This can occur if the resolver accepts queries from untrusted networks, resolves for external users, or is tricked into querying the attacker-controlled domain.
In the worst scenario, the manipulated input can not only trigger denial of service but also open the door to remote code execution using data controlled by the attacker. No active exploitation in the wild had been observed at the time of disclosure.
Unbound 1.26.1 adds a proper buffer capacity check after decompression and before writing data. The release also bundles eight additional security fixes, including CVE-2026-82717 involving heap corruption during CNAME synthesis and CVE-2026-81634 related to possible heap overflow during DNSSEC canonicalization.
Administrators are advised to update to Unbound 1.26.1 immediately. Where immediate updates are not possible, apply the official patch for CVE-2026-81642, recompile, and plan full adoption of all fixes. Organizations should also inventory Unbound instances in appliances, containers, and distribution packages to confirm the running version includes the equivalent patch.
Related articles
FBI Issues Alert on Active FortiBleed Campaign Harvesting Credentials from Exposed FortiGate Firewalls
The FBI and United States Secret Service have issued a joint alert regarding the FortiBleed campaign, an ongoing operation that targets internet-exposed FortiGate firewalls and SSL VPN gateways. Attackers have already collected 86,644 valid credentials from devices across 194 countries as of June 19, demonstrating the global scale of the indiscriminate scanning effort. The campaign relies on reused or previously leaked credentials combined with legacy SHA-256 password storage that enables offline cracking. Operators employ automated credential stuffing, the Go-based FortigateSniffer tool capable of intercepting 24 authentication protocols, and GPU-accelerated password cracking. Once inside, attackers create unauthorized administrator accounts and often delete legitimate ones, forcing victims to perform full device recovery rather than simple password resets. The activity was first documented in June, with the official alert released on October 7, confirming that scanning continues.
Cisco Patches 14 Vulnerabilities in NX-OS Software, Four Rated Critical
Cisco Systems has released security updates addressing 14 vulnerabilities in its Cisco NX-OS Software used in network devices. Four of the seven security advisories published on October 7, 2026, are rated Critical, while three are rated Medium. Several critical issues affect the Cisco Nexus 3000 Series and Nexus 9000 Series switches, impacting features such as NGOAM, MPLS OAM, and the NX-API management interface. Seven vulnerabilities received CVSSv3.1 base scores of 9.0 or higher, with multiple flaws enabling remote code execution as root or denial-of-service conditions. Specific CVEs including CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 stem from input validation failures in the NGOAM feature and may require SRv6 or NV Overlay configurations to be exploitable. The advisories also cover control plane denial-of-service issues, Python sandbox escapes, and endpoint group contract bypasses in ACI mode.
HPE Networking ClearPass Policy Manager Hit by 28 Vulnerabilities Including 10 Rated Critical
Hewlett Packard Enterprise has disclosed 28 vulnerabilities in its HPE Networking ClearPass Policy Manager product and released security updates to address them. The issues span the web management interface, APIs, endpoint agents, and client software components. Ten of the flaws received a Critical severity rating. Notable issues include SQL injection, multiple authentication bypasses, unsafe deserialization leading to remote code execution, and path traversal. No public exploit code or active discussions were observed at the time the advisory was published on October 6, 2026. The company urges customers to apply the available patches promptly.
Attackers Exploit Critical Atlassian Data Center Flaw CVE-2026-21589 Hours After PoC Release
Exploitation attempts against CVE-2026-21589 began almost immediately after technical details and a Nuclei template were published. The vulnerability allows unauthenticated arbitrary file read in multiple Atlassian Data Center products and carries a CVSS v4.0 score of 9.3. In environments integrated with Crowd, attackers who obtain crowd.properties can extract plaintext credentials and escalate to administrator privileges via the Crowd API. The flaw stems from improper handling of double-colon sequences in a shared web resource library, enabling path traversal against plugin resource endpoints. Affected products include Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian urges immediate patching outside normal cycles and recommends WAF rules or Tomcat RewriteValve configurations to block traversal patterns. Organizations should also review access logs for double-decoded URLs containing .., /, \, or :: sequences.