CVE-2026-1519Patch(isc / bind)

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch isc bind systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-606CWE-770

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bind

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 21 mentions across 12 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 14 signals
  • Technical details provided in 16 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 11d ago at 4 mentions (2026-03-25); latest day: 1
  • 21 total mentions across 12 days

Affected systems

Vendors
Products
bind

Deep dive

Activity timeline21 mentions / 12d
01234Mentions · 2026-03-25: 4Mentions · 2026-03-26: 4Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1Mentions · 2026-04-01: 1Mentions · 2026-04-02: 1Mentions · 2026-04-03: 1Mentions · 2026-04-04: 1Mentions · 2026-04-14: 1Mentions · 2026-04-15: 3Mentions · 2026-04-17: 1Active Exploitation · 2026-03-27: 1Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-26: 3Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-15: 3Patch / Workaround · 2026-04-17: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 4Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 3Technical Details · 2026-04-17: 103-2503-2603-2703-2803-3004-0104-0204-0304-0404-1404-1504-17
Signal classification5 categories
Patch
1257.1%
General
419.0%
Disclosure
314.3%
Disclousure
14.8%
Active Exploitation
14.8%
Referenced assets22 URLs
Classification over time
DateTotalLabels
2026-03-254
Disclousure1General2Patch1
2026-03-264
Disclosure1Patch3
2026-03-272
Active Exploitation1General1
2026-03-281
Patch1
2026-03-301
Disclosure1
2026-04-011
Patch1
2026-04-021
Patch1
2026-04-031
Disclosure1
2026-04-041
General1
2026-04-141
Patch1
2026-04-153
Patch3
2026-04-171
Patch1
Full discourse20 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Patch

    【注意喚起】(緊急)BIND 9.xの脆弱性(過剰なCPU負荷の誘発)について(CVE-2026-1519) - バージョンアップを強く推奨 - https://jprs.jp/tech/security/2026-03-26-bind9-vuln-nsec3.html

    Post summary

    An urgent advisory for BIND 9.x (CVE-2026-1519) warns of a vulnerability that can trigger excessive CPU load and recommends immediate upgrade, with no proof of exploitation or PoC presented.

    042911.8K
    1.3K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Disclosure

    【自分用メモ】今回は4件。 CVE-2026-1519: Excessive NSEC3 iterations cause high CPU load during insecure delegation validation https://kb.isc.org/docs/cve-2026-1519 CVE-2026-3104: Memory leak in code preparing DNSSEC proofs of non-existence https://kb.isc.org/docs/cve-2026-3104 CVE-2026-3119: Authenticated query containing a TKEY record may cause named to terminate unexpectedly https://kb.isc.org/docs/cve-2026-3119 CVE-2026-3591: A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass https://kb.isc.org/docs/cve-2026-3591

    Post summary

    The post lists four newly disclosed CVEs with short technical descriptions and links to ISC Knowledge Base pages for details.

    042711.3K
    4.4K followersView on X
  • Kazuki Omo@omokazuki
    Patch

    SIOSセキュリティブログを更新しました。 BIND 9の脆弱性(High: CVE-2026-1519, CVE-2026-3104, Medium: CVE-2026-3119, CVE-2026-3591)と9.18.47, 9.20.21, 9.21.20のリリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #dns #bind https://security.sios.jp/vulnerability/bind-security-vulnerability-20260326/

    Post summary

    The post announces BIND 9 security vulnerabilities, lists four CVEs with severity ratings, and notes the availability of patched releases.

    03033877
    360 followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    4 CVEs fixed in BIND 9 https://www.openwall.com/lists/oss-security/2026/03/25/7 CVE-2026-1519: Excessive NSEC3 iterations cause high CPU load during insecure delegation validation CVE-2026-3104: Memory leak in code preparing DNSSEC proofs of non-existence + next tweet

    Post summary

    BIND 9 has been updated to fix several vulnerabilities, including CVE‑2026‑1519, which causes high CPU usage via excessive NSEC3 iterations, and CVE‑2026‑3104, a memory‑leak in DNSSEC proof generation.

    11060545
    4.4K followersView on X
  • Toshifumi Sakaguchi@siskrn
    General

    NSEC3の負荷問題とかTKEYとか。   https://kb.isc.org/docs/cve-2026-1519   https://kb.isc.org/docs/cve-2026-3104   https://kb.isc.org/docs/cve-2026-3119   https://kb.isc.org/docs/cve-2026-3591

    Post summary

    The text lists four ISC CVE advisories related to NSEC3 and TKEY, but offers no direct technical details, PoC, or patch information within the post itself.

    01040201
    259 followersView on X
  • まこぴ@makopicut
    Patch

    [RHEL10] RHSA-2026:8312 - bind security update Security Fix(es): - Denial of Service via maliciously crafted DNSSEC-validated zone (CVE-2026-1519) https://access.redhat.com/errata/RHSA-2026:8312

    Post summary

    Red Hat released a patch for CVE‑2026‑1519, a denial‑of‑service flaw in DNSSEC handling, with no surface of active exploitation; users should apply the update.

    1000080
    116 followersView on X
  • まこぴ@makopicut
    Patch

    [RHEL8] RHSA-2026:8155 - bind9.16 security update Security Fix(es): - Denial of Service via maliciously crafted DNSSEC-validated zone (CVE-2026-1519) https://access.redhat.com/errata/RHSA-2026:8155

    Post summary

    Red Hat announced security update RHSA-2026:8155 for BIND 9.16, providing a patch to mitigate a Denial‑of‑Service vulnerability (CVE‑2026‑1519) involving DNSSEC-validated zones.

    1000062
    116 followersView on X
  • まこぴ@makopicut
    Patch

    [RHEL9] RHSA-2026:8075 - bind security update Security Fix(es): - Denial of Service via maliciously crafted DNSSEC-validated zone (CVE-2026-1519) https://access.redhat.com/errata/RHSA-2026:8075

    Post summary

    Red Hat’s RHSA-2026:8075 issues a patch for a DNSSEC-related denial‑of‑service flaw in bind on RHEL 9.

    1000044
    116 followersView on X
  • まこぴ@makopicut
    Patch

    [RHEL9] RHSA-2026:7915 - bind9.18 security update Security Fix(es): - Denial of Service via maliciously crafted DNSSEC-validated zone (CVE-2026-1519) https://access.redhat.com/errata/RHSA-2026:7915

    Post summary

    Red Hat releases errata RHSA‑2026:7915 to patch a denial‑of‑service vulnerability (CVE‑2026‑1519) in bind9.18, with a link for details.

    10000109
    116 followersView on X
  • iototsecnews@iototsecnews
    Patch

    BIND 9 の脆弱性 CVE-2026-1519 などが FIX:サーバ/プロセスの異常終了の恐れ https://iototsecnews.jp/2026/03/27/bind-9-security-flaws-allow-attackers-to-bypass-security-controls-and-crash-servers/ ISC (Internet Systems Consortium) が公開した、BIND 9 の 3 件の脆弱性について解説する記事です。この問題の原因は、DNSSEC の検証処理や署名付きクエリのハンドリング、そして、メモリ・アクセスの管理におけるプログラム上の不備にあります。 これらの脆弱性は、authoritative サーバとリゾルバの両方に影響を与えるため、ネットワーク全体の可用性と安全性を損なう大きなリスクとなります。すでに ISC は、これらの脆弱性を修正するアップデートを公開していますので、運用環境に合わせた 9.18.47/9.20.21/ 9.21.20 へのバージョンアップが推奨されています。ご利用のチームは、ご注意ください。 #BIND #CVE20261519 #CVE20263119 #CVE20263591 #Vulnerability

    Post summary

    The article discusses three BIND 9 vulnerabilities, explains their technical causes, and highlights that ISC has issued patches, urging administrators to upgrade.

    01000137
    481 followersView on X
  • CCB Alert@CCBalert
    Patch

    Two High-Severity DoS vulnerabilities in ISC #BIND9 DNS resolvers. #CVE-2026-3104 & #CVE-2026-1519 CVSS: 7.5. Memory leak & CPU exhaustion can take down your DNS infrastructure! Read our advisory https://ccb.belgium.be/advisories/warning-isc-bind-9-dns-vulnerabilities-patch-immediately. #Patch #Patch #Patch

    Post summary

    Two high‑severity DoS vulnerabilities in ISC BIND9 (CVSS 7.5) are announced; the advisory stresses immediate patching to resolve memory‑leak and CPU‑exhaustion issues.

    00010265
    7.2K followersView on X
  • Barış İnceişçi@inceisci
    Patch

    ISC, BIND'da 4 güvenlik açığı düzeltti. İkisi yüksek önemli: DNSSEC’te bellek sızıntısı ,Yüksek CPU kullanımı https://feedly.com/cve/CVE-2026-1519 #CyberSecurity #AISec

    Post summary

    ISC released a patch for BIND, addressing four vulnerabilities including a DNSSEC memory leak and high CPU usage.

    0001086
    541 followersView on X
  • まこぴ@makopicut
    Patch

    [RHEL8] RHSA-2026:8352 - bind security update Security Fix(es): - Denial of Service via maliciously crafted DNSSEC-validated zone (CVE-2026-1519) https://access.redhat.com/errata/RHSA-2026:8352

    Post summary

    Red Hat's RHSA-2026:8352 patch addresses a DoS vulnerability (CVE-2026-1519) triggered by malicious DNSSEC zones on RHEL8, with no active exploitation or PoC details mentioned.

    0000048
    116 followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 57% of vulnerabilities from past week, CVE-2026-1519 has 12 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post highlights that CVE-2026-1519 has a high number of articles, but it provides no technical details, PoC, exploit code, or patch information.

    0000060
    70 followersView on X
  • RiskdogNews@riskdog_news
    Disclosure

    BIND NSEC3によるCPU枯渇型DoS (CVE-2026-1519)が判明、JPRSが更新促す https://news.risk.dog/articles/jprs-bind-nsec3-dos-cve-2026-1519

    Post summary

    CVE-2026-1519, a CPU exhaustion DoS vulnerability in BIND’s NSEC3, has been disclosed; JPRS urges an update to mitigate the issue.

    0000057
    712 followersView on X
  • CyberTech Insights@CyberTech_In
    Disclosure

    #ISC has disclosed three @bind9 vulnerabilities, including a high-severity DoS flaw (CVE-2026-1519), along with risks of crashes and ACL bypass. https://tinyurl.com/3t9n595c #CyberSecurity #DNS #BIND9 #Infosec #Vulnerabilities https://t.co/ajVJ3rcfz7

    Post summary

    ISC announced three new BIND9 vulnerabilities, including a high‑severity DoS flaw (CVE-2026-1519) with associated crash and ACL bypass risks.

    0000054
    12 followersView on X
  • Marc-Frédéric Gomez@marcfredericgo
    Active Exploitation

    🚨 RadioCSIRT #609 — Veille Cyber du 26 mars 2026 🚨 Code Injection exploitée, DNS vulnérable, 2G en extinction et LeakBase démantelé — la pression ne faiblit pas. 👉 Aujourd'hui encore, on ne commente pas… on agit. 🔎 Au programme : ⚠️ CVE-2026-33017 — Langflow ajouté au KEV CISA → Vulnérabilité de type Code Injection activement exploitée → Plateforme open source de création de workflows IA → Exploitation confirmée dans la nature → Directive BOD 22-01 : remédiation sous délai contraint pour les agences FCEB 🌐 ISC BIND — 4 CVEs signalées par le CERT-FR → CVE-2026-1519 / 3104 / 3119 / 3591 → Branches 9.18.x, 9.20.x, 9.21.x affectées → Déni de service à distance, atteinte à la confidentialité, contournement de politique de sécurité → Surface d'exposition critique sur les infrastructures DNS 📡 Extinction du réseau 2G en France — Orange dès le 31 mars → Démarrage sur Biarritz, Bayonne, Anglet → Calendrier national jusqu'en décembre 2026 → Risque opérationnel : IoT industriel, systèmes d'alarme, terminaux M2M, SCADA → Déconnexion non anticipée = surface d'exposition opérationnelle 🔓 LeakBase — arrestation du propriétaire présumé en Russie → Résident de Taganrog interpellé dans la région de Rostov → Forum créé en 2021, 142 000 membres, issu du groupe ARES → Operation Leak : Europol + FBI + 15 pays, 100 actions coercitives → Base de données saisie — logs IP et messages privés exploités comme preuves 🎧 Écoutez l'analyse complète dans RadioCSIRT #609 👉 https://www.radiocsirt.org ⚡️ On ne réfléchit pas, on patch ! 📞 Répondeur : 07 68 72 20 09 📩 Email : radiocsirt@gmail.com 🌐 Site : https://www.radiocsirt.org 📰 Newsletter : https://radiocsirt.substack.com #CyberSecurity #CERT #CSIRT #ThreatIntelligence #Langflow #BIND #DNS #IoT #2G #LeakBase #RadioCSIRT

    Post summary

    The post alerts that CVE-2026-33017 (Langflow) is a code injection flaw actively exploited, listed on CISA KEV, with remediation directives, while also noting additional DNS and BIND CVEs facing active threats.

    0000094
    411 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-1519 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1519 #CVE-2026-1519 #CVE #High  #CyberSecurity #InfoSec https://t.co/TsCpR6K8K5

    Post summary

    The tweet announces a newly identified CVE (CVE‑2026‑1519) with a 7.5 severity score and high risk level, but offers no technical details, exploit information, or mitigation guidance.

    0000033
    123 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Canonical patches Bind vulns CVE-2026-1519, -3104, -3119, -3591 in Ubuntu 25.10, 24.04 and 22.04, closing remote DoS and ACL bypass vectors. https://threatcluster.io/cluster/critical-bind-vulnerabilities-affect-ubuntu-2510-leading-to--77433e2d

    Post summary

    Canonical released patches for CVE-2026-1519, -3104, -3119, and -3591 affecting Ubuntu 25.10, 24.04 and 22.04, addressing remote DoS and ACL bypass vectors; no active exploitation or PoC is reported.

    0000067
    115 followersView on X
  • IT関連サイト記事@itit7777
    Disclousure

    IT関連サイト記事が更新されました!記事はこちらから⇒ BIND 9の脆弱性(High: CVE-2026-1519, CVE-2026-3104, Medium: CVE-2026-3119, CVE-2026-3591)と9.18.47, 9.20.21, 9.21.20のリリース https://security.sios.jp/vulnerability/bind-security-vulnerability-20260326/

    Post summary

    The article announces new BIND 9 vulnerabilities (CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591) along with related release numbers, but provides no further technical or exploitation details.

    0000065
    448 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiscbind---

Explore more