Skip to content
Vulnerabilities

Service Outages Loom as CISA Orders Federal BIND TKEY Fixes by Oct 11

CISA added an old but active BIND vulnerability to its critical catalog, demanding federal action within three days to prevent service outages.

Service Outages Loom as CISA Orders Federal BIND TKEY Fixes by Oct 11
Illustration: Malware Brief

Key points

  • CVE-2015-5477 allows remote denial of service via TKEY queries.
  • The flaw affects ISC BIND 9.x versions prior to specific patch releases.
  • Federal agencies must apply mitigations by 11 October 2026.

The US Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies mitigate a high-severity denial-of-service vulnerability in ISC BIND by 11 October 2026. The agency added CVE-2015-5477 to its Known Exploited Vulnerabilities (KEV) catalog on 8 October, triggering strict compliance deadlines under Binding Operational Directive 26-04.

How it unfolded

  • 8 October 2026: CISA adds CVE-2015-5477 to the KEV catalog.
  • 11 October 2026: Federal due date for applying mitigations or discontinuing use.
  • The vulnerability remains active in unpatched systems, posing an ongoing risk.

Who is affected

Organisations running ISC BIND versions 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 are vulnerable. According to the National Vulnerability Database, the flaw allows remote attackers to cause a denial of service through TKEY queries. This results in a REQUIRE assertion failure and forces the daemon to exit, effectively crashing the DNS service. The Common Vulnerability Scoring System rates the issue at 7.5, classifying it as high severity. While CISA notes that ransomware use of this specific flaw is unknown, the potential for service disruption remains significant for internet-facing infrastructure.

The fix

ISC has released patches for the affected versions. The National Vulnerability Database identifies the remediation as upgrading to BIND 9.9.7-P2 or 9.10.2-P3. However, CISA’s guidance emphasises that stakeholders must evaluate each asset’s internet exposure. If mitigations are unavailable, agencies are instructed to discontinue use of the product. Compliance requires following vendor instructions and adhering to CISA’s forensics triage requirements. For cloud services, applicable BOD 26-04 guidance must be followed.

What to do and how to stay safe: ISC BIND

  • Inventory all DNS servers to identify instances of BIND 9.x running versions older than 9.9.7-P2 or 9.10.2-P3.
  • Restrict access to DNS services from untrusted networks to reduce the attack surface for TKEY queries.
  • Monitor system logs for unexpected daemon exits or assertion failures that may indicate exploitation attempts.
  • Verify that cloud-based DNS configurations comply with federal security update directives if applicable.

Step-by-step guide: Patch Management: Eight Questions Answered for Stability

General security guidance from the Malware Brief newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is CVE-2015-5477?

It is a data processing error in ISC BIND that allows remote attackers to cause a denial of service via TKEY queries.

Which BIND versions are vulnerable?

Versions 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 are affected.

When must federal agencies act?

The deadline for mitigation is 11 October 2026.

Sources

  1. CISA KEV catalog
ISC BINDCVE-2015-5477CISADNSDenial of Service

Related stories

Organizations urged to check SSL certs after hackers hijacked .gh, .sl, .as to forge Google HTTPS

Attackers hijacked three country-code top-level domains to issue unauthorised HTTPS certificates for Google properties, though core systems remained secure.

Cybersecurity news without the noiseDaily Briefing