Back to all news
Security

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

The Hacker News·September 17, 2026·1 min read
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

NLnet Labs disclosed a critical heap overflow in the DNSSEC validator of every Unbound DNS resolver release before 1.26.1, tracked as CVE-2026-81642. An attacker controlling a malicious zone can trigger it via a query, enabling remote code execution. Unbound 1.26.1, released Wednesday, fixes the flaw. Administrators are urged to update immediately to prevent exploitation.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store