Recommended Free Tools
Internet Systems Consortium (ISC) disclosed a remotely exploitable, high-severity denial-of-service flaw in BIND 9 on September 16, 2026. A vulnerable resolver can spend excessive CPU time building a DNS response when queried for the root of a cached SVCB/HTTPS AliasMode record tree. ISC rates the issue CVSS 7.5 (High); it reports no known workaround and no awareness of active exploitation. Administrators should identify their BIND branch and move to a fixed, supported maintenance release.
Which BIND versions are affected?
ISC’s September 16, 2026 advisory identifies these affected ranges and fixes for CVE-2026-81736:
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Network Security, Firewalls, and VPNs | $66.62 | Buy on Amazon |
| 2 |
|
Network Security, Firewalls, and VPNs: . (Issa) | $60.26 | Buy on Amazon |
| 3 |
|
TP-Link ER605, Wired Gigabit VPN Router | $49.99 | Buy on Amazon |
| 4 |
|
Cybersecurity for Small Networks: A Guide for the Reasonably Paranoid | $34.58 | Buy on Amazon |
| BIND branch | Affected versions | ISC fix |
|---|---|---|
| 9.18 | 9.18.0–9.18.50 | No fix for this branch is listed in the advisory. ISC ended 9.18 maintenance at the end of June 2026. |
| 9.20 | 9.20.0–9.20.27 | 9.20.29 |
| 9.21 | 9.21.0–9.21.25 | 9.21.26 |
| Supported preview | Listed supported-preview ranges | 9.20.29-S1 |
The advisory does not enumerate the preview ranges in the information summarized here, so preview users should check ISC’s CVE-2026-81736 notice for the exact range and applicable package. A fixed version is a minimum correction, not a reason to remain on an older maintenance release: ISC recommends using the latest maintenance release on a supported branch.
What causes the denial of service?
The vulnerable path involves SVCB or HTTPS AliasMode records. If a resolver has cached a tree of these records and receives a query for the tree’s root, it may use disproportionate CPU while constructing the answer. Repeated queries can exhaust resolver resources and make DNS service unavailable. The attack is remote; the relevant weakness is the resolver’s response-processing path, not a need for an attacker to log in to the DNS server.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
ISC assigns CVE-2026-81736 a CVSS score of 7.5 (High). It says no workaround is known and that it is not aware of active exploits. Those statements describe ISC’s assessment at disclosure; they do not mean an unpatched resolver is safe to expose.
Two related September 2026 BIND DoS advisories
ISC disclosed two additional high-severity denial-of-service issues in the same update. They have different triggers, so administrators should include them in the same patch review rather than treating the AliasMode issue as the only relevant risk.
Rank #2
- Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
- New Chapter on detailing network topologies
- The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
- Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
- Increased coverage on device implantation and configuration
| CVE | Described trigger or effect | CVSS | Fixed versions listed |
|---|---|---|---|
| CVE-2026-81563 | Resource leakage when an AliasMode record references 14 or more ServiceMode records. | 7.5 (High) | 9.20.29 and 9.21.26 |
| CVE-2026-19666 | A specially malformed authoritative answer can cause the named process to exit on a DNS64-configured resolver. | 7.5 (High) | 9.20.29 and 9.21.26 |
The information available for these related notices does not establish their full affected-version ranges. Check each ISC advisory against the exact BIND build and platform in use instead of assuming that a version range from CVE-2026-81736 applies to all three.
How to assess and patch a BIND deployment
- Inventory the running build. Check the version reported by the running BIND installation and confirm whether it is a standard release or a supported preview. Compare that exact build with the affected ranges above; do not rely only on a package’s major or branch label.
- Check the resolver’s role and features. Determine whether the instance performs recursive resolution for clients you do not fully trust, whether its workload may involve SVCB/HTTPS AliasMode data, and whether DNS64 is configured. These details help prioritize exposure and the related advisories; they do not replace upgrading.
- Select a supported maintenance release. For a 9.20 or 9.21 deployment, install at least the fixed release shown in the table, preferably the newest maintenance release available for that supported branch. A 9.18 installation needs a planned move to a maintained branch: ISC ended 9.18 maintenance at the end of June 2026, and the 9.18 package listing does not make that branch a current security-fix target.
- Apply the vendor’s package or build. Follow the operating-system vendor’s or ISC’s instructions for the platform, then restart or reload BIND as required by that package’s update procedure. Confirm the running process reports the intended version after the change.
- Validate service and coverage. Check that the resolver starts cleanly, answers expected queries, and that monitoring sees normal DNS service. Verify every recursive resolver and failover node was upgraded; patching only the primary leaves other instances in scope.
Why branch support status matters
ISC’s May 2026 maintenance-policy announcement said users should expect security fixes in every monthly BIND maintenance release for the foreseeable future. It also said 9.18 maintenance would end at the close of June 2026 and advised users to plan an update to 9.20. As a result, remediation is not just a choice between affected and fixed patch numbers: it also requires confirming that the selected branch continues to receive security maintenance.
Rank #3
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
ISC’s BIND download page lists packages including 9.20.29 and 9.18.50, but a package appearing on a download page does not by itself establish ongoing security support. Use the branch policy and the specific vulnerability advisory to choose a supported target, and subscribe to ISC’s bind-announce list for release and vulnerability notices.
Quick Recap
Sources
- Internet Systems Consortium, CVE-2026-81736, published September 16, 2026.
- Internet Systems Consortium, CVE-2026-81563 and CVE-2026-19666, September 2026 advisories.
- Vicky Risk, Internet Systems Consortium, BIND maintenance-policy announcement, May 2026.
- Internet Systems Consortium, BIND downloads and release notices.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

