Service Outages Loom as CISA Orders Federal BIND TKEY Fixes by Oct 11
CISA added an old but active BIND vulnerability to its critical catalog, demanding federal action within three days to prevent service outages.

Key points
- CVE-2015-5477 allows remote denial of service via TKEY queries.
- The flaw affects ISC BIND 9.x versions prior to specific patch releases.
- Federal agencies must apply mitigations by 11 October 2026.
The US Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies mitigate a high-severity denial-of-service vulnerability in ISC BIND by 11 October 2026. The agency added CVE-2015-5477 to its Known Exploited Vulnerabilities (KEV) catalog on 8 October, triggering strict compliance deadlines under Binding Operational Directive 26-04.
How it unfolded
- 8 October 2026: CISA adds CVE-2015-5477 to the KEV catalog.
- 11 October 2026: Federal due date for applying mitigations or discontinuing use.
- The vulnerability remains active in unpatched systems, posing an ongoing risk.
Who is affected
Organisations running ISC BIND versions 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 are vulnerable. According to the National Vulnerability Database, the flaw allows remote attackers to cause a denial of service through TKEY queries. This results in a REQUIRE assertion failure and forces the daemon to exit, effectively crashing the DNS service. The Common Vulnerability Scoring System rates the issue at 7.5, classifying it as high severity. While CISA notes that ransomware use of this specific flaw is unknown, the potential for service disruption remains significant for internet-facing infrastructure.
The fix
ISC has released patches for the affected versions. The National Vulnerability Database identifies the remediation as upgrading to BIND 9.9.7-P2 or 9.10.2-P3. However, CISA’s guidance emphasises that stakeholders must evaluate each asset’s internet exposure. If mitigations are unavailable, agencies are instructed to discontinue use of the product. Compliance requires following vendor instructions and adhering to CISA’s forensics triage requirements. For cloud services, applicable BOD 26-04 guidance must be followed.
What to do and how to stay safe: ISC BIND
- Inventory all DNS servers to identify instances of BIND 9.x running versions older than 9.9.7-P2 or 9.10.2-P3.
- Restrict access to DNS services from untrusted networks to reduce the attack surface for TKEY queries.
- Monitor system logs for unexpected daemon exits or assertion failures that may indicate exploitation attempts.
- Verify that cloud-based DNS configurations comply with federal security update directives if applicable.
Step-by-step guide: Patch Management: Eight Questions Answered for Stability
General security guidance from the Malware Brief newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
What is CVE-2015-5477?
It is a data processing error in ISC BIND that allows remote attackers to cause a denial of service via TKEY queries.
Which BIND versions are vulnerable?
Versions 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 are affected.
When must federal agencies act?
The deadline for mitigation is 11 October 2026.



