SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-10723

MEDIUM · CVSS 6.8 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

BIND versions 9.18.0 to 9.18.50, 9.20.0 to 9.20.24, 9.21.0 to 9.21.23, and specific S1 versions may incorrectly validate child-zone NSEC3 records, allowing attackers to forge authenticated NXDOMAIN responses. This vulnerability could lead to DNS spoofing, potentially disrupting services and misleading users. Organizations using affected BIND versions should prioritize patching to mitigate the risk of DNS-related attacks.

CVE
CVE-2026-10723
Severity
MEDIUM
CVSS
6.8
EPSS
0.27%

Original NVD Description

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.