Yasuhiro Morishita[verified]@OrangeMorishitaDisclosure
The memo documents four newly disclosed ISC DNS vulnerabilities, outlining their technical nature but providing no PoC, exploit, or patch information.
DNSAudit.io[verified]@dnsauditDisclosure
CVE-2026-3591 is a newly disclosed use‑after‑return flaw in BIND 9's SIG(0) handling that can cause ACL mismatches and IP restriction bypass. Patching and upgrading to the latest release are recommended.
Gray Hats@the_yellow_fallPatch
The tweet announces that BIND 9 has released patches for a critical ACL bypass (CVE‑2026‑3591) and a high‑severity CPU exhaustion bug, directing readers to an advisory link.
日本レジストリサービス(JPRS)@JPRS_officialPatch
The notice warns of an ACL bypass vulnerability (CVE-2026-3591) affecting both resolver and authoritative DNS servers in BIND 9.20.x, strongly recommending an upgrade to mitigate the risk.
Kazuki Omo@omokazukiPatch
SIOS security blog announces BIND 9 vulnerabilities (CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591) and the release of patched versions 9.18.47, 9.20.21, and 9.21.20.
Toshifumi Sakaguchi@siskrnGeneral
The post references four CVEs tied to NSEC3 load issues and TKEY and links to official documentation, but offers no further technical detail, PoC, or evidence of exploitation.
日本レジストリサービス(JPRS)@JPRS_officialGeneral
The JPRS e‑magazine issue references CVE‑2026‑3591, a BIND 9.20.x ACL bypass vulnerability, but provides no PoC, exploit tool, active‑exploitation claim, or patch details.
Open Source Security mailing list@oss_securityPatch
BIND 9 releases address CVE‑2026‑3119 (a TKEY query crash) and CVE‑2026‑3591 (a stack use‑after‑return ACL bypass) without reported active exploitation.