CVE-2026-10723
Received Received - Intake

DNSSEC Validation Bypass in BIND

Vulnerability report for CVE-2026-10723, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: Internet Systems Consortium (ISC)

Description

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
isc bind From 9.18.0 (inc) to 9.18.50 (inc)
isc bind From 9.20.0 (inc) to 9.20.24 (inc)
isc bind From 9.21.0 (inc) to 9.21.23 (inc)
isc bind From 9.11.3-S1 (inc) to 9.18.50-S1 (inc)
isc bind From 9.20.9-S1 (inc) to 9.20.24-S1 (inc)
isc bind 9.20.26
isc bind 9.21.24

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

BIND may incorrectly accept invalid child-zone NSEC3 records as valid. This allows an attacker to forge authenticated NXDOMAIN responses, potentially manipulating DNS data for sibling zones.

Detection Guidance

Check BIND version with 'named -v' or 'rpm -qa | grep bind' to confirm if affected versions (9.18.0-9.18.50, 9.20.0-9.20.24, 9.21.0-9.21.23) are running. Monitor DNS query logs for unexpected NXDOMAIN responses or child-zone NSEC3 record anomalies.

Impact Analysis

An attacker could forge DNS responses, leading to misdirection to malicious sites or denial of service. This could disrupt network services relying on BIND for DNS resolution.

Compliance Impact

The vulnerability could impact compliance by enabling DNS cache poisoning or misdirection, potentially leading to unauthorized data exposure or service disruption. This may violate requirements for data integrity and confidentiality in GDPR and HIPAA.

Mitigation Strategies
  • Upgrade BIND to patched versions 9.20.26, 9.21.24, or their Supported Preview Edition updates (9.20.26-S1).
  • Apply patches from ISC download links for 9.20.26 or 9.21.24 immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10723. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart