Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3666 articles · 197852 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-3039EXPLOITEDPATCHED
isc · bind

BIND 9 server memory exhaustion during GSS-API TKEY negotiation

Description

BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-secured DNS environments. This issue affects BIND 9 versions 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

Affected Products

VendorProductVersions
iscbind9.0.0, 9.18.0, 9.20.0, 9.21.0, 9.9.3-S1, 9.18.11-S1, 9.20.9-S1

References

  • https://kb.isc.org/docs/cve-2026-3039(vendor-advisory)
  • https://downloads.isc.org/isc/bind9/9.18.49(patch)
  • https://downloads.isc.org/isc/bind9/9.20.23(patch)
  • https://downloads.isc.org/isc/bind9/9.21.22(patch)

Related News (5 articles)

Tier B
CERT-FR19d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier A
Microsoft MSRC95d ago
CVE-2026-3039 BIND 9 server memory exhaustion during GSS-API TKEY negotiation
→ No new info (linked only)
Tier C
oss-security98d ago
ISC has disclosed six vulnerabilities in BIND 9 (CVE-2026-3039, CVE-2026-3592, CVE-2026-3593, CVE-2026-5946, CVE-2026-5947, CVE-2026-5950)
→ No new info (linked only)
Tier C
VulDB98d ago
CVE-2026-3039 | ISC BIND up to 9.21.21 GSS-API Token missing reference to active allocated resource
→ No new info (linked only)
Tier B
CERT-FR98d ago
Multiples vulnérabilités dans ISC BIND (20 mai 2026)
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
https://kb.isc.org/docs/cve-2026-3039https://downloads.isc.org/isc/bind9/9.18.49https://downloads.isc.org/isc/bind9/9.20.23
CWECWE-771
PublishedMay 20, 2026
Last enriched98d agov2
Tags
CVE-2026-3592CVE-2026-3593
Trending Score4
Source articles5
Independent4
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-13321
DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
Trending: 2
HIGHCVE-2026-11622
Potential memory usage beyond configured limits
Trending: 1
HIGHCVE-2026-11721
Cache poisoning possible with label count discrepancy, RRSIG, and wildcards
Trending: 1
HIGHCVE-2026-13204
Unexpected exit in certain situations with NSEC and NSEC3 both present
Trending: 1
HIGHCVE-2026-11605
Unnecessary validation of DNSSEC signed records
Trending: 1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 20, 2026
Discovered by ZDM
May 20, 2026
Updated: exploitAvailable, activelyExploited, tags
May 20, 2026
Actively Exploited
Aug 25, 2026
Exploit Available
Aug 25, 2026
Patch Available
Aug 25, 2026

Version History

v2
Last enriched 98d ago
v2Tier B98d ago

Updated exploit availability to true, marked as actively exploited, and added new CVE tags.

exploitAvailableactivelyExploitedtags
via CERT-FR
v198d ago

Initial creation