Cyber Intelligence

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Medium Severity Global
Date Occurred Sep 17, 2026 12:30 UTC
Event Type Cyber Intelligence
Source TheHackerNews
Recorded Sep 17, 2026
Full Description

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who control

Event Metadata
  • ID #32331
  • Type Cyber Intelligence
  • Region Global
  • Severity Medium
  • Indexed Sep 17, 2026