Unbound DNS resolver versions before 1.26.1 contain a critical heap overflow in the DNSSEC validator that can let an attacker achieve remote code execution through a malicious zone. The 1.26.1 release fixes CVE-2026-81642 plus eight other flaws, including CVE-2026-82717 in CNAME synthesis, and users are advised to upgrade or apply the provided patches. #Unbound #CVE-2026-81642 #CVE-2026-82717 #NLnetLabs #CISA
Keypoints
- Unbound before 1.26.1 has a critical heap overflow in its DNSSEC validator.
- An attacker controlling a malicious zone can trigger remote code execution.
- CVE-2026-81642 affects every version up to and including 1.26.0.
- Unbound 1.26.1 fixes nine vulnerabilities, including CVE-2026-82717.
- NLnet Labs recommends upgrading or applying the supplied source patches.
Read More: https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html