Threat reportVulnerabilityTL-2026-0599

BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)

highMONITORING

BIND 9 Multi-CVE Disclosure (May 2026) (TL-2026-0599), also tracked as BIND 9 May 2026 Disclosure, is a high-severity software vulnerability scored CVSS 7.5, first published 2026-05-27. It has no confirmed attribution, affects ISC BIND 9 (9.11 branch), references 6 CVEs (CVE-2026-3593, CVE-2026-5947, CVE-2026-5950), maps to 20 MITRE ATT&CK techniques (T1018, T1027, T1046), and is covered by 9 detection rules and 21 indicators of compromise.

CVSS
7.5/10High
CVEs
6Referenced vulnerabilities
Techniques
20MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-0599

Threat ID
TL-2026-0599
Also known as
BIND 9 May 2026 Disclosure, ISC BIND 9 Vulnerability Matrix May 2026 Update
Severity
HIGH
CVSS
7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Status
MONITORING
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, healthcare, telecommunications, internet-service-providers, education, technology, cloud-providers, critical-infrastructure, enterprise-it
Target regions
Global
Detection rules
9
Indicators of compromise
21

Malware and tooling in BIND 9 Multi-CVE Disclosure (May 2026)

Malware and tooling: dig / kdig / dnsperf / scapy / custom HTTP/2 fuzzers

How BIND 9 Multi-CVE Disclosure (May 2026) works

ISC disclosed six remotely exploitable vulnerabilities in BIND 9 on 20 May 2026 (CVE-2026-3593, CVE-2026-5950, CVE-2026-5947, CVE-2026-5946, CVE-2026-3592, CVE-2026-3039), affecting recursive resolvers and authoritative name servers across the 9.11, 9.16, 9.18, 9.20, and 9.21 branches. Impacts span heap use-after-free in DNS-over-HTTPS (potential memory corruption / RCE), SIG(0) race-condition UAF, unbounded resolver resend loops, assertion-failure crashes on non-IN classes, query amplification via self-pointed glue records, and GSS-API TKEY-driven memory exhaustion. ISC has released fixed versions 9.18.49, 9.20.23, and 9.21.22; no in-the-wild exploitation has been reported.

On 20 May 2026, the Internet Systems Consortium (ISC) publicly disclosed six new CVEs in BIND 9 — the most widely deployed open-source DNS server — and refreshed its centralized BIND 9 Software Vulnerability Matrix to map each CVE to affected and fixed releases. The matrix is the canonical reference operators use to determine exposure; this disclosure adds entries #169 through #174 covering both resolver-side and authoritative-side defects. All six issues are remotely exploitable by unauthenticated attackers, four are rated High by ISC, and two are rated Medium. ISC issued early notifications to subscribers on 13 May 2026 and synchronized public disclosure across all six advisories on 20 May 2026.

CVE-2026-3593 — Heap use-after-free in BIND 9 DNS-over-HTTPS (DoH) implementation (CVSS 7.4, High, AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H). A use-after-free condition exists in BIND's DoH code path. An attacker who can reach a DoH-enabled BIND instance with crafted HTTP/2 traffic can trigger memory corruption, which under specific conditions may permit arbitrary code execution; the more likely outcome is named crash and information disclosure from the freed heap region. The flaw affects BIND 9.20.0 → 9.20.22, BIND 9.21.0 → 9.21.21, and Supported Preview 9.20.9-S1 → 9.20.22-S1. The 9.18 branch is not affected. Both authoritative servers and resolvers are vulnerable if they enable DoH listeners. Disabling DoH is an effective mitigation pending patch.

CVE-2026-5947 — SIG(0) validation race condition during query flood (CVSS 7.5, High, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). A race condition between SIG(0) signature validation and the recursive-clients quota produces a use-after-free / dangling-pointer read. When a SIG(0)-signed inbound DNS message is being validated and the recursive-clients limit is simultaneously reached, that same message may be discarded while validation is still reading from its memory. Result: segmentation faults / named aborts. Code execution from the improper read is considered unlikely. Affects BIND 9.20.0 → 9.20.22 and 9.21.0 → 9.21.21; 9.18.28 → 9.18.49 is not affected.

CVE-2026-5950 — Unbounded resend loop in BIND 9 resolver (CVSS 5.3, Medium, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). A defect in the resolver state machine's bad-server handling permits an attacker-induced query pattern to enter a retry loop with no upper bound, exhausting CPU and memory on the resolver and causing sustained denial-of-service across all clients relying on that resolver. The vulnerability is reachable by remote unauthenticated attackers that can induce the target to issue resolution attempts (e.g., by visiting attacker-controlled domains or sending queries that traverse the resolver). Affects 9.18.36 → 9.18.48, 9.20.8 → 9.20.22, 9.21.7 → 9.21.21. No workaround; patch only.

CVE-2026-5946 — Invalid handling of CLASS != IN (CVSS 7.5, High, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Multiple flaws in named's handling of DNS messages whose CLASS is not Internet (IN) — for example CHAOS or HESIOD, or meta-classes ANY/NONE in the question section. Specially crafted requests reaching recursion, dynamic update (UPDATE), zone-change notification (NOTIFY), or IN-specific record-type processing in non-IN data trigger assertion failures inside named, terminating the daemon and producing denial-of-service. Affects an extraordinarily wide range — 9.11.0 → 9.16.50, 9.18.0 → 9.18.48, 9.20.0 → 9.20.22, 9.21.0 → 9.21.21 — encompassing many EoL deployments. Workarounds: avoid configuring non-IN zones and do not expose Dynamic Update interfaces to untrusted networks.

CVE-2026-3592 — Amplification vulnerabilities via self-pointed glue records (CVSS 5.3, Medium, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L). A recursive resolver that queries a maliciously authored zone containing glue records that point back into themselves expends disproportionate bandwidth and TCP resources attempting to resolve the name, creating an amplification/exhaustion primitive abusable for reflected DDoS. Authoritative-only servers that do not perform recursion are believed unaffected. Affects 9.11.0 → 9.16.50, 9.18.0 → 9.18.48, 9.20.0 → 9.20.22, 9.21.0 → 9.21.21.

CVE-2026-3039 — Memory exhaustion during GSS-API TKEY negotiation (CVSS 7.5, High, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). BIND servers configured for TKEY-based GSS-API authentication (typically Active Directory-integrated DNS or Kerberos-secured environments) leak memory on processing maliciously constructed TKEY packets. Sustained packet streams will drive named to OOM termination. Affects 9.0.0 → 9.16.50, 9.18.0 → 9.18.48, 9.20.0 → 9.20.22, 9.21.0 → 9.21.21 — and ISC explicitly states all EoL versions are presumed vulnerable. No workaround.

Operational picture: BIND 9 underpins resolution for enterprise networks, ISPs, ccTLD/gTLD operators, AD-integrated forests, and embedded appliances. DoH listeners (CVE-2026-3593) are increasingly enabled on resolver fleets serving privacy-sensitive clients; AD-DNS deployments (CVE-2026-3039) are common across Windows enterprise estates; recursive resolvers exposed to client queries (CVE-2026-5950, CVE-2026-3592) cover the broad ISP and corporate base. Attackers do not need privileged access — every issue is exploitable from a network position that can reach the affected listener, and the resend-loop and CLASS!=IN issues can be triggered by indirect means (visiting a malicious URL, prompting a recursive lookup). No active exploitation has been observed at disclosure, but the disclosure detail (especially the DoH heap UAF and the SIG(0) UAF) gives capable actors enough surface area to build reliable triggers. Operators on 9.20.x and 9.21.x are the highest-risk population because they are vulnerable to the largest number of these CVEs simultaneously.

MITRE ATT&CK techniques used in TL-2026-0599

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

Defense Evasion

T1027 Obfuscated Files or Information

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution

Impact

T1489 Service Stop; T1496 Resource Hijacking; T1498 Network Denial of Service; T1498.002 Network Denial of Service: Reflection Amplification; T1499 Endpoint Denial of Service; T1499.003 Endpoint Denial of Service: Application Exhaustion Flood; T1499.004 Endpoint Denial of Service: Application or System Exploitation

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.002 Acquire Infrastructure: DNS Server; T1583.004 Acquire Infrastructure: Server; T1587.004 Develop Capabilities: Exploits

Reconnaissance

T1590 Gather Victim Network Information; T1590.002 Gather Victim Network Information: DNS; T1595.002 Active Scanning: Vulnerability Scanning

Affected products and versions in BIND 9 Multi-CVE Disclosure (May 2026)

  • ISC — BIND 9 (9.11 branch)
    Vulnerable versions: 9.11.0 - 9.16.50 (CVE-2026-5946, CVE-2026-3592); 9.0.0 - 9.16.50 (CVE-2026-3039)
    Fixed in: EOL — upgrade to 9.18.49+ or supported branch
  • ISC — BIND 9 (9.18 branch)
    Vulnerable versions: 9.18.0 - 9.18.48 (CVE-2026-5946, CVE-2026-3592, CVE-2026-3039); 9.18.36 - 9.18.48 (CVE-2026-5950)
    Fixed in: 9.18.49
  • ISC — BIND 9 (9.20 branch)
    Vulnerable versions: 9.20.0 - 9.20.22 (all six CVEs); 9.20.8 - 9.20.22 (CVE-2026-5950)
    Fixed in: 9.20.23
  • ISC — BIND 9 (9.21 branch)
    Vulnerable versions: 9.21.0 - 9.21.21 (all six CVEs); 9.21.7 - 9.21.21 (CVE-2026-5950)
    Fixed in: 9.21.22
  • ISC — BIND Supported Preview Edition (-S1)
    Vulnerable versions: 9.11.3-S1 - 9.16.50-S1; 9.18.11-S1 - 9.18.48-S1; 9.20.9-S1 - 9.20.22-S1
    Fixed in: 9.18.49-S1; 9.20.23-S1

Remediation for BIND 9 Multi-CVE Disclosure (May 2026)

Patches

  • BIND 9.18.49 (fixes CVE-2026-5950, CVE-2026-5946, CVE-2026-3592, CVE-2026-3039)
  • BIND 9.20.23 (fixes all six CVEs)
  • BIND 9.21.22 (fixes all six CVEs)
  • BIND Supported Preview Edition: 9.18.49-S1, 9.20.23-S1

Immediate actions

  • Inventory all BIND 9 deployments and identify which branches/versions are in use (9.11, 9.16, 9.18, 9.20, 9.21, Supported Preview -S1).
  • Disable DNS-over-HTTPS (DoH) listeners on any 9.20.x/9.21.x deployment that does not require DoH (mitigates CVE-2026-3593) until patches are applied.
  • Restrict Dynamic Update (UPDATE) interfaces and DNS service exposure to the public internet where possible (mitigates CVE-2026-5946).
  • For AD-integrated DNS deployments, restrict TKEY/GSS-API endpoints to trusted Kerberos-enrolled networks (mitigates CVE-2026-3039).

Workarounds

  • CVE-2026-3593: disable DoH listeners
  • CVE-2026-5946: avoid configuring non-IN class zones; do not expose Dynamic Update to the internet
  • CVE-2026-5947, CVE-2026-5950, CVE-2026-3592, CVE-2026-3039: no workarounds known — patch required

Longer-term hardening

  • Upgrade to BIND 9.18.49, 9.20.23, or 9.21.22 (or matching -S1 Supported Preview releases) — the only complete fix for all six CVEs.
  • Retire EoL branches (9.0–9.16); ISC declares them presumed insecure and unpatched (only CVE-2026-5946 and CVE-2026-3592 affect 9.11/9.16 in the supported lineage, but EoL versions accumulate prior unpatched CVEs).
  • Avoid running alpha/beta/release-candidate BIND in production.
  • Implement DNS query rate limiting and Response Rate Limiting (RRL) on resolvers to dampen amplification (CVE-2026-3592) and resend-loop (CVE-2026-5950) abuse.
  • Audit DoH endpoints behind reverse proxies / WAFs that can absorb HTTP/2 abuse traffic before it reaches named.
  • Add monitoring for named process restarts, RSS growth, and CPU spikes correlated with anomalous query volume.

CVEs associated with BIND 9 Multi-CVE Disclosure (May 2026)

CVE-2026-3593, CVE-2026-5947, CVE-2026-5950, CVE-2026-5946, CVE-2026-3592, CVE-2026-3039

Weaknesses (CWE) in BIND 9 Multi-CVE Disclosure (May 2026)

CWE-416, CWE-362, CWE-835, CWE-400, CWE-617, CWE-405, CWE-401, CWE-20

Timeline of BIND 9 Multi-CVE Disclosure (May 2026)

  • ISC issues early notification (advisory version 1.0) to entitled subscribers for all six CVEs simultaneously (CVE-2026-3593, CVE-2026-5950, CVE-2026-5947, CVE-2026-5946, CVE-2026-3592, CVE-2026-3039).
  • CVE-2026-3039 advisory revised to v1.1 — references to keytab removed (using GSS-API TKEY is sufficient for exposure).
  • CVE Records published for all six identifiers on cve.org with ISC as CNA.
  • ISC publishes all six advisories at version 2.0 and releases fixed BIND versions 9.18.49, 9.20.23, 9.21.22, plus Supported Preview 9.18.49-S1 and 9.20.23-S1. BIND 9 Vulnerability Matrix (aa-00913) updated with entries #169-#174.
  • Threadlinqs Intelligence publishes TL-2026-0599 bundling all six CVEs with full MITRE mapping, IOCs, and detection coverage.
  • Cyber Security News publishes analysis highlighting CVE-2026-3593 (DoH heap UAF with RCE potential) and CVE-2026-5950 (unbounded resend loop DoS) as the highest-impact issues in the bundle.
  • As of 2026-05-29, this 20 May 2026 ISC BIND 9 six-CVE bundle (incl. DoH heap-UAF CVE-2026-3593 with RCE potential) remains a live concern: patches (9.18.49/9.20.23/9.21.22) shipped at disclosure but the vulnerable population is vast, trigger detail is public, and no CVE is yet on CISA KEV. ISC and multiple outlets report no in-the-wild exploitation, so contained but watch for emerging PoCs.

Sources cited for BIND 9 Multi-CVE Disclosure (May 2026)

Detection coverage for TL-2026-0599

As of 2026-05-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0599 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats