Insufficient verification of data authenticity in ISC BIND - CVE-2026-19033
Published: September 16, 2026
Vulnerability details
The vulnerability allows a remote attacker to add arbitrary data to a zone.
The vulnerability exists due to improper verification of TSIG signatures in named IXFR processing when processing a multi-message TCP IXFR for a TSIG-restricted secondary zone. A remote attacker can send an IXFR transfer without a valid TSIG signature to add arbitrary data to a zone.
Affected software
Debian Linux
bind9 (Debian package)
How to mitigate CVE-2026-19033
bind9 (Debian package) - update to 1:9.20.29-1~deb13u1