CuraSec

Act active

Critical Unbound DNS RCE via Malicious DNSSEC Zone (CVE-2026-81642)

2026-09-17 15:32 UTC · The Hacker News · read the source ↗ #dns#rce#dnssec
  • Engineer — Act: A public PoC exists for this critical heap overflow enabling RCE against any Unbound resolver that validates DNSSEC; patch to Unbound 1.26.1 immediately and verify all resolver deployments (containers, host-based, service mesh sidecars) are updated.
  • SOC/IR — Learn: No active exploitation or IOCs reported, and EPSS is 0.01; the attack path (attacker-controlled zone triggers RCE in resolver) is worth noting for future hunt hypotheses, but no detection work is warranted until exploitation evidence emerges.
  • Leader — Skip
  • Signals: CVE-2026-81642 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.