CyberSecurity News
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
AI summary
A critical heap overflow vulnerability has been discovered in the Unbound DNS resolver's DNSSEC validator, affecting all versions prior to 1.26.1. This flaw can be triggered by an attacker controlling a malicious DNS zone and querying a vulnerable resolver, potentially allowing remote code execution. The issue is tracked as CVE-2026-81642 and has been fixed in Unbound version 1.26.1, which was released to address the bug. The vulnerability can be exploited by an attacker who controls a malicious zone and queries a vulnerable resolver. NLnet Labs, the maintainer of Unbound, issued an advisory to inform users of the critical flaw. The fix is available in Unbound 1.26.1, released on the same day as the advisory.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

