Act
active
Critical Unbound DNS RCE via Malicious DNSSEC Zone (CVE-2026-81642)
- Engineer — Act: A public PoC exists for this critical heap overflow enabling RCE against any Unbound resolver that validates DNSSEC; patch to Unbound 1.26.1 immediately and verify all resolver deployments (containers, host-based, service mesh sidecars) are updated.
- SOC/IR — Learn: No active exploitation or IOCs reported, and EPSS is 0.01; the attack path (attacker-controlled zone triggers RCE in resolver) is worth noting for future hunt hypotheses, but no detection work is warranted until exploitation evidence emerges.
- Leader — Skip
- Signals: CVE-2026-81642 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.