CVE-2026-3593Disclosure(isc / bind)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch isc bind systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through 9.18.48 and 9.18.11-S1 through 9.18.48-S1 are NOT affected.

2.3/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-416CWE-825

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bind

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 15 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 12 signals
  • Disclosure: 6 classified signals
  • General: 3 classified signals
  • Peaked 10d ago at 3 mentions (2026-05-20); latest day: 1
  • 15 total mentions across 11 days

Affected systems

Vendors
Products
bind

Deep dive

Activity timeline15 mentions / 11d
01223Mentions · 2026-05-20: 3Mentions · 2026-05-21: 3Mentions · 2026-05-23: 1Mentions · 2026-05-24: 1Mentions · 2026-05-25: 1Mentions · 2026-05-27: 1Mentions · 2026-06-03: 1Mentions · 2026-06-06: 1Mentions · 2026-06-07: 1Mentions · 2026-06-12: 1Mentions · 2026-09-09: 1PoC Mentioned / Linked · 2026-06-06: 1PoC Mentioned / Linked · 2026-06-07: 1Patch / Workaround · 2026-05-20: 2Patch / Workaround · 2026-05-21: 3Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-24: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-06-06: 1Patch / Workaround · 2026-06-07: 1Technical Details · 2026-05-20: 2Technical Details · 2026-05-21: 2Technical Details · 2026-05-23: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 1Technical Details · 2026-05-27: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-06: 1Technical Details · 2026-06-07: 1Technical Details · 2026-06-12: 105-2005-2105-2305-2405-2505-2706-0306-0606-0706-1209-09
Signal classification4 categories
Disclosure
640.0%
Patch
533.3%
General
320.0%
PoC
16.7%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-05-203
Disclosure1General1Patch1
2026-05-213
Disclosure1Patch2
2026-05-231
Patch1
2026-05-241
Disclosure1
2026-05-251
Disclosure1
2026-05-271
Patch1
2026-06-031
Disclosure1
2026-06-061
Disclosure1
2026-06-071
PoC1
2026-06-121
General1
2026-09-091
General1
Full discourse15 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Patch

    【注意喚起】(緊急)BIND 9.20.xの脆弱性(メモリ破壊の発生)について(CVE-2026-3593) - DNS over HTTPSが有効に設定されている場合のみ対象、バージョンアップを強く推奨 - https://jprs.jp/tech/security/2026-05-21-bind9-vuln-dnsoverhttps.html

    Post summary

    The notice warns users of a memory‑corruption flaw (CVE‑2026‑3593) affecting BIND 9.20.x only when DNS‑over‑HTTPS is enabled, and strongly advises upgrading to the latest version.

    04061713
    1.3K followersView on X
  • Yu F@fj_twt
    Patch

    CVE-2026-3593: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation https://kb.isc.org/docs/cve-2026-3593

    Post summary

    ISC’s advisory for CVE-2026-3593 identifies a heap use‑after‑free flaw in BIND 9’s DNS‑over‑HTTPS, and provides information on the available patch.

    01241671
    1.6K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    BIND9の脆弱性(High: CVE-2026-3039, CVE-2026-3593, CVE-2026-5946, CVE-2026-5947, Medium: CVE-206-3592, CVE-206-5950)と9.18.49, 9.20.23, 9.21.22公開 #sios_tech #security #vulnerability #セキュリティ #脆弱性 #dns #bind https://security.sios.jp/vulnerability/bind-security-vulnerability-20260520/

    Post summary

    The post announces several BIND9 CVEs alongside the release of patched versions 9.18.49, 9.20.23, and 9.21.22.

    04020356
    370 followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    General

    https://kb.isc.org/docs/cve-2026-3039 https://kb.isc.org/docs/cve-2026-3592 https://kb.isc.org/docs/cve-2026-3593 https://kb.isc.org/docs/cve-2026-5946 https://kb.isc.org/docs/cve-2026-5947 https://kb.isc.org/docs/cve-2026-5950

    Post summary

    The text lists links to ISC Knowledge Base pages for a series of CVEs, but contains no explicit information about PoCs, exploits, or mitigations.

    03120377
    4.5K followersView on X
  • Aretiq.AI@AretiqAI
    PoC

    CVE-2026-3593 | ISC BIND 9 DoH Use-After-Free HTTP/2 SETTINGS floods trigger server_read_callback on a freed response buffer. Crashes ASAN builds ~40%/round. Pre-auth. Fixed in BIND 9.20.23 / 9.21.22. Analysis + PoC: https://aretiq.ai/research/10/

    Post summary

    ISC BIND 9 DoH use‑after‑free vulnerability (CVE‑2026‑3593) disclosed with technical details, PoC link, and patch information.

    00030173
    132 followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【BINDに複数脆弱性、DNS運用者は更新確認を】 JVNは、BINDに複数の脆弱性が存在すると公表しました。 対象には CVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950 が含まれ、サービス運用妨害やメモリ破壊につながる可能性が示されています。 DNSは停止時の影響が広範囲に及ぶため、外部公開DNSだけでなく、内部リゾルバや委託先のDNS運用状況も確認が必要です。 日本の組織では、BINDのバージョン、namedの異常終了、SERVFAIL急増、DNS監視と冗長化の状態を週明けに確認したいところです。 #BIND #DNS #JVN #CVE #脆弱性対応 #インフラ運用 #SOC https://jvn.jp/vu/JVNVU99225456/index.html

    Post summary

    JVN disclosed multiple CVEs affecting BIND, highlighting potential service disruption and memory corruption, and urged organizations to verify updates and monitor DNS operations.

    01020318
    3.7K followersView on X
  • Aretiq.AI@AretiqAI
    Disclosure

    CVE-2026-3593 — ISC BIND 9 DoH Use-After-Free HTTP/2 SETTINGS floods trigger server_read_callback to read freed response buffers. ~40% crash rate per round on hardened builds. One-line fix: nullify wbuf before freeing the request. Full analysis + PoC: https://aretiq.ai/research/10/

    Post summary

    The post announces the discovery of CVE-2026‑3593 in ISC BIND 9, provides technical details, a PoC link, and a simple mitigation, but does not report active exploitation or a functional exploit.

    0001070
    82 followersView on X
  • كاسبر سكاي@KasperskyDev
    Patch

    ⚠️ ثغرة عالية الخطورة في أكثر برامج خوادم أسماء النطاق انتشاراً، تتيح تعطيل الخادم أو تنفيذ كود عن بُعد. المنتج : ISC BIND 9 (DoH) المعرّف : CVE-2026-3593 الخطورة : High - Heap UAF الإصدارات : 9.20.x / 9.21.x الحل : Update to 9.20.23 / 9.21.6 #CVE #BIND #DNS

    Post summary

    A high‑severity heap UAF vulnerability (CVE-2026-3593) in ISC BIND 9 (DoH) can lead to remote code execution or server disablement; applying the update to 9.20.23 or 9.21.6 resolves the issue.

    10000302
    40.0K followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    【ISC BINDに複数脆弱性、DNS可用性への影響に注意】 JVNは、ISC BINDにおける複数の脆弱性を公開しました。対象にはCVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950が含まれ、DoS、メモリ破損、use-after-free、再送信ループなどが想定されています。 DNSはメール、Web、クラウド、認証基盤の前提となるため、停止や遅延が広範な業務影響につながります。特に権威DNS、キャッシュDNS、DNS-over-HTTPSを運用している組織は、対象バージョンと設定を確認する必要があります。 日本のSOCは、BINDのバージョン、namedの異常終了、メモリ使用量、SERVFAIL急増、クエリ遅延を監視し、冗長系を考慮して計画的にアップデートしてください。 #BIND #DNS #JVN #CVE #脆弱性 #サイバーセキュリティ #SOC https://jvn.jp/vu/JVNVU99225456/index.html

    Post summary

    ISC BIND multiple CVEs are disclosed with technical details and the text emphasizes monitoring and updating to mitigate the risks.

    00010232
    3.7K followersView on X
  • hands_of_cat@hands_of_cat
    General

    「bind vulnerability use after free remote code」とかをググって、CVE-2026-3593 の Windows DNS版かな?とかあたりをつけてみる。

    Post summary

    The user is searching for more information on CVE-2026-3593, but provides no concrete evidence, exploit details, or additional context.

    0000081
    339 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-3593: BIND 9 DNS-over-HTTPS Use-After-Free Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04lct930

    Post summary

    The text refers to a blog article describing CVE-2026-3593, a use‑after‑free bug in BIND 9 DNS‑over‑HTTPS, and advises on how to respond, but offers no PoC, exploit tools, or active exploitation evidence.

    0000031
    31 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    BIND 9 の複数の脆弱性が FIX:サービス拒否 (DoS)/メモリ破損/リモート攻撃などの恐れ https://iototsecnews.jp/2026/05/27/bind-9-software-vulnerabilities-exposes-resolvers-and-authoritative-servers-to-remote-exploits/ BIND 9 に発生した一連の脆弱性は、 メモリ管理の不備/特定のクエリを処理する際のループ制御/リソースの制限不足などに起因するものである。脆弱性 CVE-2026-3593 では、DNS-over-HTTPS (DoH) 機能において、すでに解放されたメモリ領域に誤ってアクセスされる設計上の弱点が存在します。 また、CVE-2026-5950 では リゾルバの処理ロジックにおいて無限に処理が繰り返されてしまう不備があり、外部からの通信によりシステムリソースが枯渇し、サービス拒否を招く恐れがあります。ご利用のチームは、ご注意ください。 #BIND9 #CVE20263039 #CVE20263592 #CVE20265946 #CVE20265947 #Vulnerability

    Post summary

    The article reports newly disclosed BIND 9 vulnerabilities (CVE‑2026‑3593, CVE‑2026‑5950, etc.), describing memory and resource exhaustion weaknesses, but provides no PoC, exploit, or patch information.

    0000097
    491 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    CVE-2026-3593: Critical (9.8) heap use-after-free in BIND 9's DNS-over-HTTPS. Affects 9.20.x, 9.21.x & S1 builds. Patch to 9.20.23, 9.21.22, or 9.20.23-S1 now. #BIND https://secalerts.co/vulnerability/CVE-2026-3593

    Post summary

    The post announces a newly disclosed, critical heap use‑after‑free vulnerability in BIND 9’s DNS‑over‑HTTPS, providing affected versions and the applicable patch.

    0000078
    826 followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【BIND 9に複数脆弱性、DNS運用者は更新確認を】 JVNは、ISC BINDにおける複数の脆弱性を公表しました。対象にはCVE-2026-3039、CVE-2026-3592、CVE-2026-3593、CVE-2026-5946、CVE-2026-5947、CVE-2026-5950が含まれます。 影響は脆弱性ごとに異なりますが、遠隔攻撃者によるサービス運用妨害、メモリ破損、namedのクラッシュなどが想定されています。権威DNS、キャッシュDNS、DNS-over-HTTPS有効環境など、構成によって確認すべき範囲が変わります。 DNSは障害時の業務影響が大きい基盤です。日本の組織は、BINDのバージョン、namedの再起動履歴、メモリ使用量、DoH設定、パッチ適用可否を早急に確認すべきです。 #BIND #DNS #JVN #脆弱性 #CVE #インフラセキュリティ #SOC https://jvn.jp/vu/JVNVU99225456/

    Post summary

    The post announces multiple newly disclosed BIND 9 vulnerabilities (CVE-2026-3039/3592/3593/5946/5947/5950) and urges Japanese organizations to verify BIND versions and patch status, but does not provide exploit code or active exploitation reports.

    00000264
    3.7K followersView on X
  • su8 / denchu@__su888
    Patch

    ISCがBIND 9.20.23/9.18.49を5月20日にリリース。リゾルバのサーバリスト肥大化(CVE-2026-3592)、GSS-API TKEYのリソースリーク、DoHのHTTP/2でのuse-after-free(CVE-2026-3593)など複数脆弱性を修正 / ISC、「BIND 9.20.23/9.18.49」リリース ─ 複数の脆弱性を修正 https://thinkit.co.jp/news/39215

    Post summary

    ISC released BIND 9.20.23/9.18.49 on May 20 to fix multiple vulnerabilities, including CVE‑2026‑3592, CVE‑2026‑3593, and a GSS‑API TKEY resource leak; no PoC, exploit, or active exploitation details are provided.

    00000116
    791 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appiscbind---

Explore more