Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3565 articles · 197874 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-11721PATCHED
isc · bind

Cache poisoning possible with label count discrepancy, RRSIG, and wildcards

Description

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Affected Products

VendorProductVersions
iscbind9.11.0, 9.20.0, 9.21.0, 9.11.3-S1, 9.20.9-S1

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
debiandebian linuxcert_advisory90%
internet systems consortiumbindcert_advisory90%

References

  • https://kb.isc.org/docs/cve-2026-11721(vendor-advisory)
  • https://downloads.isc.org/isc/bind9/9.20.26(patch)
  • https://downloads.isc.org/isc/bind9/9.21.24(patch)

Related News (3 articles)

Tier B
BSI Advisories34d ago
[NEU] [hoch] Internet Systems Consortium BIND: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security35d ago
ISC has disclosed nine vulnerabilities in BIND 9 (CVE-2026-10723, CVE-2026-10822, CVE-2026-11331, CVE-2026-11605, CVE-2026-11622, CVE-2026-11721, CVE-2026-12617, CVE-2026-13204, CVE-2026-13321)
→ No new info (linked only)
Tier C
VulDB35d ago
CVE-2026-11721 | ISC BIND up to 9.21.23 DNSSEC Validation input validation
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://kb.isc.org/docs/cve-2026-11721https://downloads.isc.org/isc/bind9/9.20.26https://downloads.isc.org/isc/bind9/9.21.24
CWECWE-1284
PublishedJul 22, 2026
Last enriched35d agov2
Trending Score1
Source articles3
Independent3
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-13321
DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
Trending: 2
HIGHCVE-2026-11622
Potential memory usage beyond configured limits
Trending: 1
HIGHCVE-2026-13204
Unexpected exit in certain situations with NSEC and NSEC3 both present
Trending: 1
HIGHCVE-2026-11605
Unnecessary validation of DNSSEC signed records
Trending: 1
HIGHCVE-2026-12617
Record ordering based unexpected exit with CNAME or DNAME
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026
Updated: severity, cweIds
Jul 22, 2026
Patch Available
Jul 22, 2026

Version History

v2
Last enriched 35d ago
v2Tier C35d ago

Updated severity from HIGH to CRITICAL and added CWE-20 (Improper Input Validation) based on article classification.

severitycweIds
via VulDB
v135d ago

Initial creation