PatchSiren cyber security CVE debrief
CVE-2026-3039 ISC CVE debrief
ISC BIND 9 servers configured with TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption. This primarily affects Active Directory integrated DNS deployments and Kerberos-secured DNS environments. The issue spans multiple BIND 9 versions, including 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, and 9.21.0 through 9.21.21. Affected servers may experience performance degradation or crashes due to memory consumption, potentially leading to denial-of-service conditions.
- Vendor
- ISC
- Product
- BIND 9
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-20
- Original CVE updated
- 2026-09-17
- Advisory published
- 2026-05-20
- Advisory updated
- 2026-09-17
Who should care
Defenders managing BIND 9 servers, especially in Active Directory integrated DNS deployments and Kerberos-secured DNS environments, should assess exposure and prioritize patching. This includes verifying patch deployment, reviewing compensating controls, and tracking exceptions for exposed systems. Inventory management and exposure assessment are crucial for prioritizing patching efforts and ensuring mitigation.
Why it matters
CVE-2026-3039 is a high-severity vulnerability in ISC BIND 9 that can lead to excessive memory consumption and potential denial-of-service conditions. Defenders, especially those managing Active Directory integrated DNS or Kerberos-secured DNS environments, should prioritize patching and verify exposure.
- Memory consumption could lead to performance degradation or crashes, requiring emergency response and potential downtime.
- Successful exploitation could result in denial-of-service conditions, impacting DNS resolution services.
- Defenders need to verify patch deployment to ensure mitigation.
- Exposure assessment and inventory management are crucial for prioritizing patching efforts.
Technical summary
BIND 9 servers configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Affected versions include 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and specific service releases. This vulnerability can lead to performance degradation or crashes, potentially resulting in denial-of-service conditions. Defenders should prioritize patching, especially for servers in Active Directory integrated DNS or Kerberos-secured DNS environments.
Defensive priority
Defenders should prioritize patching, especially for servers in Active Directory integrated DNS or Kerberos-secured DNS environments.
Recommended defensive actions
- Patch affected BIND 9 servers, especially those in Active Directory integrated DNS or Kerberos-secured DNS environments.
- Inventory BIND 9 servers to identify exposure.
- Verify patch deployment for BIND 9 servers.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE and NVD records provide details on affected BIND 9 versions and configurations. Patches are available for multiple versions, including 9.18.49, 9.20.23, and 9.21.22. Defenders should verify patch deployment to ensure mitigation and review compensating controls for exposed systems. The vulnerability is a result of maliciously-constructed packets being processed by BIND 9 servers, highlighting the need for exposure assessment and inventory management.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-3039 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-3039
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-3039 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3039
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://downloads.isc.org/isc/bind9/9.18.49
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://downloads.isc.org/isc/bind9/9.20.23
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://downloads.isc.org/isc/bind9/9.21.22
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://kb.isc.org/docs/cve-2026-3039
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:20334
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:23360
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:24338
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:24339
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.