Threat Intelligence

Critical Flaw in Unbound DNS Software Could Let Attackers Run Malicious Code

The Hacker News · 17 Sept 2026
Key Takeaway Businesses running Unbound DNS resolvers should upgrade to version 1.26.1 as soon as possible to close off this remote code execution risk.

NLnet Labs, the maintainer of the widely used Unbound DNS resolver, has disclosed a critical security flaw affecting every version released before 1.26.1. The bug, tracked as CVE-2026-81642, is a heap overflow in the software's DNSSEC validator. An attacker who controls a malicious DNS zone can trigger the flaw simply by having a vulnerable resolver query it, potentially leading to remote code execution on the affected system.

The fix, released in Unbound 1.26.1, also addresses eight other vulnerabilities. One of these, CVE-2026-82717, is a separate heap corruption bug related to CNAME processing that could also allow remote code execution under certain system configurations. NLnet Labs has not reported any active exploitation of either flaw, and the US Cybersecurity and Infrastructure Security Agency listed exploitation status as 'none' at the time of publication. NLnet Labs itself has rated the DNSSEC validator bug as Critical, giving it a severity score of 9.1 out of 10.

Every Unbound release up to and including version 1.26.0 is affected, including recent security updates from July and August. NLnet Labs has not clarified whether resolvers with DNSSEC validation disabled are exposed to this issue. Version 1.26.1 is available now as source code, Windows installers, and binaries, and the advisory also provides patch options for organisations unable to upgrade immediately.

DNS Security Vulnerability Unbound DNSSEC Patch Management

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.