Isc: community verdicts
3 notable / known-exploited Isc CVEs the community has triaged.
Exploitation first, with newly exploited CVEs rising above old ones
- CVE-2026-5950MED 5.3EPSS 1%
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
- CVE-2000-1029CRIT 10EPSS 14%
Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query.
- CVE-2000-0887MED 5EPSS 23%
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone transfer (ZXFR) request and performing a name service query on an authoritative record that is not cached, aka the "zxfr bug."