Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Unbound DNS resolver versions before 1.26.1 contain a critical heap overflow in the DNSSEC validator that can let an attacker achieve remote code execution through a malicious zone. The 1.26.1 release fixes CVE-2026-81642 plus eight other flaws, including CVE-2026-82717 in CNAME synthesis, and users are advised to upgrade or apply the provided patches. #Unbound #CVE-2026-81642 #CVE-2026-82717 #NLnetLabs #CISA

Keypoints

  • Unbound before 1.26.1 has a critical heap overflow in its DNSSEC validator.
  • An attacker controlling a malicious zone can trigger remote code execution.
  • CVE-2026-81642 affects every version up to and including 1.26.0.
  • Unbound 1.26.1 fixes nine vulnerabilities, including CVE-2026-82717.
  • NLnet Labs recommends upgrading or applying the supplied source patches.

Read More: https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html