CVE-2026-3592Disclosure(isc / bind)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch isc bind systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-408

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bind

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-05-21); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
bind

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-05-20: 1Mentions · 2026-05-21: 4Mentions · 2026-05-23: 1Mentions · 2026-05-25: 1Patch / Workaround · 2026-05-21: 3Patch / Workaround · 2026-05-23: 1Technical Details · 2026-05-21: 3Technical Details · 2026-05-23: 1Technical Details · 2026-05-25: 105-2005-2105-2305-25
Signal classification3 categories
Disclosure
342.9%
Patch
342.9%
General
114.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-05-201
General1
2026-05-214
Disclosure1Patch3
2026-05-231
Disclosure1
2026-05-251
Disclosure1
Full discourse7 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Patch

    【注意喚起】BIND 9.xの脆弱性(ネットワーク帯域の過剰な消費、TCPの通信障害の発生)について(CVE-2026-3592) - バージョンアップを強く推奨 - https://jprs.jp/tech/security/2026-05-21-bind9-vuln-resourceexhaustion.html

    Post summary

    An advisory for CVE‑2026‑3592 warns of excessive network bandwidth usage and TCP failures in BIND 9.x, urging users to upgrade promptly.

    05061856
    1.3K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    General

    https://kb.isc.org/docs/cve-2026-3039 https://kb.isc.org/docs/cve-2026-3592 https://kb.isc.org/docs/cve-2026-3593 https://kb.isc.org/docs/cve-2026-5946 https://kb.isc.org/docs/cve-2026-5947 https://kb.isc.org/docs/cve-2026-5950

    Post summary

    The text simply lists links to knowledge base pages for several CVEs, providing no explicit information about exploits, patches, or technical details.

    03120377
    4.5K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【BINDに複数脆弱性、DNS運用者は更新確認を】 JVNは、BINDに複数の脆弱性が存在すると公表しました。 対象には CVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950 が含まれ、サービス運用妨害やメモリ破壊につながる可能性が示されています。 DNSは停止時の影響が広範囲に及ぶため、外部公開DNSだけでなく、内部リゾルバや委託先のDNS運用状況も確認が必要です。 日本の組織では、BINDのバージョン、namedの異常終了、SERVFAIL急増、DNS監視と冗長化の状態を週明けに確認したいところです。 #BIND #DNS #JVN #CVE #脆弱性対応 #インフラ運用 #SOC https://jvn.jp/vu/JVNVU99225456/index.html

    Post summary

    The post announces multiple CVEs affecting BIND, highlighting potential service disruption and memory corruption, and urges verification of BIND versions and DNS operations.

    01020318
    3.7K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【ISC BINDに複数脆弱性、DNS可用性への影響に注意】 JVNは、ISC BINDにおける複数の脆弱性を公開しました。対象にはCVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950が含まれ、DoS、メモリ破損、use-after-free、再送信ループなどが想定されています。 DNSはメール、Web、クラウド、認証基盤の前提となるため、停止や遅延が広範な業務影響につながります。特に権威DNS、キャッシュDNS、DNS-over-HTTPSを運用している組織は、対象バージョンと設定を確認する必要があります。 日本のSOCは、BINDのバージョン、namedの異常終了、メモリ使用量、SERVFAIL急増、クエリ遅延を監視し、冗長系を考慮して計画的にアップデートしてください。 #BIND #DNS #JVN #CVE #脆弱性 #サイバーセキュリティ #SOC https://jvn.jp/vu/JVNVU99225456/index.html

    Post summary

    The announcement details multiple ISC BIND vulnerabilities (CVE‑2026‑3039, 3592, 3593, 5946, 5947, 5950), describing their impact and urging timely patching, but provides no PoC, exploit code, or evidence of current exploitation.

    00010232
    3.7K followersView on X
  • ねこさん⚡(ΦωΦ)@catnap707
    Disclosure

    JVNVU#99225456: ISC BINDにおける複数の脆弱性(2026年5月) https://jvn.jp/vu/JVNVU99225456/ "遠隔の攻撃者によって、サービス運用妨害(DoS)攻撃を引き起こされる(CVE-2026-3039、CVE-2026-3592、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950)" https://t.co/M7l9Giby22

    Post summary

    The post announces multiple ISC BIND CVEs (2026‑xxx) that could allow remote attackers to perform DoS, but it does not provide PoC, exploit details, patches, or technical specifics.

    00001206
    3.5K followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    【BIND 9に複数脆弱性、DNS運用者は更新確認を】 JVNは、ISC BINDにおける複数の脆弱性を公表しました。対象にはCVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950が含まれます。 影響は脆弱性ごとに異なりますが、遠隔攻撃者によるサービス運用妨害、メモリ破損、namedのクラッシュなどが想定されています。権威DNS、キャッシュDNS、DNS-over-HTTPS有効環境など、構成によって確認すべき範囲が変わります。 DNSは障害時の業務影響が大きい基盤です。日本の組織は、BINDのバージョン、namedの再起動履歴、メモリ使用量、DoH設定、パッチ適用可否を早急に確認すべきです。 #BIND #DNS #JVN #脆弱性 #CVE #インフラセキュリティ #SOC https://jvn.jp/vu/JVNVU99225456/

    Post summary

    JVN disclosed multiple CVEs for ISC BIND 9, highlighting potential memory corruption and service disruption; the announcement urges DNS operators to check BIND versions and patch status promptly.

    00000264
    3.7K followersView on X
  • su8 / denchu@__su888
    Patch

    ISCがBIND 9.20.23/9.18.49を5月20日にリリース。リゾルバのサーバリスト肥大化(CVE-2026-3592)、GSS-API TKEYのリソースリーク、DoHのHTTP/2でのuse-after-free(CVE-2026-3593)など複数脆弱性を修正 / ISC、「BIND 9.20.23/9.18.49」リリース ─ 複数の脆弱性を修正 https://thinkit.co.jp/news/39215

    Post summary

    ISC released BIND 9.20.23/9.18.49 on May 20, fixing several vulnerabilities such as CVE-2026-3592 and CVE-2026-3593, along with a GSS‑API TKEY resource leak. The announcement focuses on the patch release and does not discuss exploits or active attacks.

    00000116
    791 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiscbind---

Explore more