CVE-2026-3591Patch(isc / bind)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch isc bind systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-305CWE-562

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bind

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 4 mentions (2026-03-25); latest day: 1
  • 11 total mentions across 6 days

Affected systems

Vendors
Products
bind

Deep dive

Activity timeline11 mentions / 6d
01234Mentions · 2026-03-25: 4Mentions · 2026-03-26: 3Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-03-30: 1Mentions · 2026-04-02: 1Patch / Workaround · 2026-03-25: 2Patch / Workaround · 2026-03-26: 2Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 3Technical Details · 2026-03-28: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-02: 103-2503-2603-2703-2803-3004-02
Signal classification3 categories
Patch
545.5%
Disclosure
436.4%
General
218.2%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-254
Disclosure1General1Patch2
2026-03-263
Disclosure1Patch2
2026-03-271
Disclosure1
2026-03-281
Patch1
2026-03-301
General1
2026-04-021
Disclosure1
Full discourse11 posts
  • Yasuhiro Morishita@OrangeMorishita
    Disclosure

    【自分用メモ】今回は4件。 CVE-2026-1519: Excessive NSEC3 iterations cause high CPU load during insecure delegation validation https://kb.isc.org/docs/cve-2026-1519 CVE-2026-3104: Memory leak in code preparing DNSSEC proofs of non-existence https://kb.isc.org/docs/cve-2026-3104 CVE-2026-3119: Authenticated query containing a TKEY record may cause named to terminate unexpectedly https://kb.isc.org/docs/cve-2026-3119 CVE-2026-3591: A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass https://kb.isc.org/docs/cve-2026-3591

    Post summary

    The memo documents four newly disclosed ISC DNS vulnerabilities, outlining their technical nature but providing no PoC, exploit, or patch information.

    042711.3K
    4.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    BIND 9 patches critical flaws including a sneaky ACL bypass (CVE-2026-3591) and a High-severity CPU exhaustion bug. Secure your DNS infrastructure now. #BIND9 #DNS #CyberSecurity #InfoSec #PatchAlert #ISC #Networking #SysAdmin #Vulnerability #TechNews https://securityonline.info/isc-bind-9-dns-security-advisory-acl-bypass-dos-cve-2026/ https://t.co/xxnsa51gNy

    Post summary

    The tweet announces that BIND 9 has released patches for a critical ACL bypass (CVE‑2026‑3591) and a high‑severity CPU exhaustion bug, directing readers to an advisory link.

    02062517
    10.9K followersView on X
  • 日本レジストリサービス(JPRS)@JPRS_official
    Patch

    【注意喚起】BIND 9.20.xの脆弱性(ACLのバイパス)について(CVE-2026-3591) - フルリゾルバー(キャッシュDNSサーバー)/権威DNSサーバーの双方が対象、バージョンアップを強く推奨 - https://jprs.jp/tech/security/2026-03-26-bind9-vuln-sig0.html

    Post summary

    The notice warns of an ACL bypass vulnerability (CVE-2026-3591) affecting both resolver and authoritative DNS servers in BIND 9.20.x, strongly recommending an upgrade to mitigate the risk.

    02061615
    1.3K followersView on X
  • Kazuki Omo@omokazuki
    Patch

    SIOSセキュリティブログを更新しました。 BIND 9の脆弱性(High: CVE-2026-1519, CVE-2026-3104, Medium: CVE-2026-3119, CVE-2026-3591)と9.18.47, 9.20.21, 9.21.20のリリース #sios_tech #security #vulnerability #セキュリティ #脆弱性 #dns #bind https://security.sios.jp/vulnerability/bind-security-vulnerability-20260326/

    Post summary

    SIOS security blog announces BIND 9 vulnerabilities (CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591) and the release of patched versions 9.18.47, 9.20.21, and 9.21.20.

    03033877
    360 followersView on X
  • Toshifumi Sakaguchi@siskrn
    General

    NSEC3の負荷問題とかTKEYとか。   https://kb.isc.org/docs/cve-2026-1519   https://kb.isc.org/docs/cve-2026-3104   https://kb.isc.org/docs/cve-2026-3119   https://kb.isc.org/docs/cve-2026-3591

    Post summary

    The post references four CVEs tied to NSEC3 load issues and TKEY and links to official documentation, but offers no further technical detail, PoC, or evidence of exploitation.

    01040201
    259 followersView on X
  • 日本レジストリサービス(JPRS)@JPRS_official
    General

    【メールマガジン(FROM JPRS)】最新号を掲載しました。 通常号 vol.1239「BIND 9.20.xの脆弱性(ACLのバイパス)について(CVE-2026-3591)、他3件」など https://jprs.jp/mail/backnumber/2026/260330.html

    Post summary

    The JPRS e‑magazine issue references CVE‑2026‑3591, a BIND 9.20.x ACL bypass vulnerability, but provides no PoC, exploit tool, active‑exploitation claim, or patch details.

    00040299
    1.3K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    CVEs fixed in BIND 9 CVE-2026-3119: Authenticated query containing a TKEY record may cause named to terminate unexpectedly CVE-2026-3591: A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass

    Post summary

    BIND 9 releases address CVE‑2026‑3119 (a TKEY query crash) and CVE‑2026‑3591 (a stack use‑after‑return ACL bypass) without reported active exploitation.

    00010229
    4.4K followersView on X
  • DNSAudit.io@dnsaudit
    Disclosure

    ⚠️ BIND 9 Flaw Affects ACL Matching in DNS Requests https://kb.isc.org/docs/cve-2026-3591 CVE-2026-3591 affects BIND 9, introducing a use-after-return flaw in SIG(0) handling that can cause ACL mismatches. A crafted DNS request may bypass IP-based restrictions in default-allow configurations, leading to unauthorized access. Impacts versions 9.20.x and 9.21.x. No known exploits yet, but patching is recommended. Default-deny ACLs remain safer. Upgrade to the latest fixed release and review ACL behavior to reduce exposure. Both authoritative servers and resolvers are affected. #DNS #InfoSec #DNSSecurity

    Post summary

    CVE-2026-3591 is a newly disclosed use‑after‑return flaw in BIND 9's SIG(0) handling that can cause ACL mismatches and IP restriction bypass. Patching and upgrading to the latest release are recommended.

    0000043
    13 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-3591 📊 Severity: 5.4 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3591 #CVE-2026-3591 #CVE #Medium  #CyberSecurity #InfoSec https://t.co/8r519RTJlf

    Post summary

    The tweet announces CVE-2026-3591 with a medium severity rating, referencing the NVD entry, but provides no technical details, PoC, or exploitation information.

    0000028
    123 followersView on X
  • IT関連サイト記事@itit7777
    Patch

    IT関連サイト記事が更新されました!記事はこちらから⇒ BIND 9の脆弱性(High: CVE-2026-1519, CVE-2026-3104, Medium: CVE-2026-3119, CVE-2026-3591)と9.18.47, 9.20.21, 9.21.20のリリース https://security.sios.jp/vulnerability/bind-security-vulnerability-20260326/

    Post summary

    The article announces BIND 9 CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591 and lists new releases 9.18.47, 9.20.21, 9.21.20, indicating patched versions.

    0000065
    448 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3591 - A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass Intel Report: https://ift.tt/XiIfBqz

    Post summary

    The post announces CVE-2026-3591, detailing a stack use‑after‑return flaw that could allow ACL bypass, but offers no PoC, exploit, or patch information.

    0000045
    286 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiscbind---

Explore more