Upgrade to Unbound 1.26.1 immediately. Until patched, consider restricting recursive queries to trusted clients and monitoring DNS traffic for anomalies. Apply vendor patches as soon as possible.
Quick answers
What is CVE-2026-81642?
Upgrade to Unbound 1.26.1 immediately. Until patched, consider restricting recursive queries to trusted clients and monitoring DNS traffic for anomalies. Apply vendor patches as soon as possible.
How severe is CVE-2026-81642?
critical
Is CVE-2026-81642 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-81642 be mitigated?
Upgrade to Unbound 1.26.1 immediately. Until patched, consider restricting recursive queries to trusted clients and monitoring DNS traffic for anomalies. Apply vendor patches as soon as possible.
CVSS
—
Vendor
NLnet Labs
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
Unbound
Mitigation
Upgrade to Unbound 1.26.1 immediately. Until patched, consider restricting recursive queries to trusted clients and monitoring DNS traffic for anomalies. Apply vendor patches as soon as possible.
A critical heap overflow vulnerability in the DNSSEC validator of the Unbound DNS resolver, tracked as CVE-2026-81642, could allow remote code execution by an attacker who controls a malicious DNS zone. NLnet Labs has released Unbound 1.26.1 to address the flaw, urging immediate upgrades.