[WID-SEC-2026-2484] Internet Systems Consortium BIND: Mehrere Schwachstellen CVSS Base Score 8.6 (hoch) CVSS Temporal Score 7.5 (hoch) Remoteangriff ja Datum 22.07.2026 Stand 23.07.2026 Mitigation ja Betroffene Systeme Betriebssystem UNIX Windows Produktbeschreibung BIND (Berkeley Internet Name Domain) ist ein Open-Source-Softwarepaket, das einen Domain-Name-System-Server implementiert. Produkte 22.07.2026 Debian Linux Internet Systems Consortium BIND <9.20.26 Internet Systems Consortium BIND <9.21.24 Internet Systems Consortium BIND Supported Preview Edition <9.20.26-S1 Angriff Angriff Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand auszulösen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple vulnerabilities in ISC BIND (CVSS Base Score 8.6) allow a remote, anonymous attacker to bypass security controls, manipulate data, disclose information, or cause a denial-of-service condition. Affected versions include BIND versions prior to 9.20.26, prior to 9.21.24, and Supported Preview Edition prior to 9.20.26-S1. A mitigation is available according to the advisory, but specific patch or workaround details are not provided in the summary.