
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13321 is a DNSSEC validation bypass vulnerability in ISC BIND 9 where the resolver incorrectly accepts validly-signed NSEC records whose "Next Domain Name" field points outside the signer's zone. This flaw enables cross-zone DNS cache poisoning with the Authenticated Data (AD=1) flag set, allowing an attacker controlling any DNSSEC-signed zone to inject fraudulent DNS records into victim zones. Affected versions include BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and corresponding BIND Supported Preview Edition (S1) branches. The vulnerability was disclosed on July 22, 2026, and carries a CVSS v3.1 base score of 8.6 (High) (Red Hat Advisory, GitHub Advisory).
The root cause is an Origin Validation Error (CWE-346): BIND's DNSSEC validation logic fails to enforce that an NSEC record's "Next Domain Name" field must remain within the signing zone's authority. An attacker who controls any legitimately DNSSEC-signed zone can craft NSEC records whose "Next Domain Name" spans into a victim zone, and BIND will accept these records as validly signed. Because the records carry a valid DNSSEC signature, the resolver caches them with the AD (Authenticated Data) flag set, effectively bypassing zone boundary enforcement. No special privileges or user interaction are required — the attack is network-accessible with low complexity (Red Hat Bugzilla, GitHub Advisory).
Successful exploitation allows an unauthenticated network attacker to poison the DNS cache of a vulnerable BIND resolver with fraudulent records that appear DNSSEC-authenticated (AD=1), effectively undermining the integrity guarantees of DNSSEC. This can redirect users and services relying on the resolver to attacker-controlled servers, enabling phishing, credential harvesting, man-in-the-middle attacks, or interception of sensitive communications. There is no confidentiality or availability impact directly, but the high integrity impact with a changed scope means downstream systems trusting the resolver's DNSSEC validation are also affected (Red Hat Bugzilla, GitHub Advisory).
attacker.example.).victim.com.), spanning zone boundaries.rndc dumpdb and inspection of the cache dump for cross-zone NSEC entries with AD flag set).ISC has released patched versions of BIND 9: 9.20.26 and 9.21.24 are available for download and address this vulnerability (GitHub Advisory). Administrators should upgrade to these fixed versions as the primary remediation. As interim mitigations, restrict DNS resolver access to trusted internal networks only, and monitor BIND logs for anomalous NSEC record processing. Implementing additional DNS security controls and hardening DNSSEC validation on downstream services can reduce exposure until patching is complete (Red Hat Advisory, ISC Advisory).
The vulnerability was reported to Red Hat's security response team via OSIDB on July 21, 2026, and publicly disclosed the following day. Red Hat has classified it as high severity and opened a tracking bug. The ISC published an official knowledge base article detailing the issue. Community aggregators including OSS-Sec, VulDB, and security intelligence platforms picked up the disclosure within hours of publication, indicating broad awareness in the DNS and security community (Red Hat Bugzilla, ISC Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."