HackerFeeds

CyberSecurity News

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

The Hacker News
· September 17, 2026

AI summary

A critical heap overflow vulnerability has been discovered in the Unbound DNS resolver's DNSSEC validator, affecting all versions prior to 1.26.1. This flaw can be triggered by an attacker controlling a malicious DNS zone and querying a vulnerable resolver, potentially allowing remote code execution. The issue is tracked as CVE-2026-81642 and has been fixed in Unbound version 1.26.1, which was released to address the bug. The vulnerability can be exploited by an attacker who controls a malicious zone and queries a vulnerable resolver. NLnet Labs, the maintainer of Unbound, issued an advisory to inform users of the critical flaw. The fix is available in Unbound 1.26.1, released on the same day as the advisory.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.