Internet Systems Consortium (ISC)
Self-Reporting Analysis
Of all the CVEs published by Internet Systems Consortium (ISC) as a CNA, 79.3% affect products that Internet Systems Consortium (ISC) develops as a vendor.
Of all the CVEs published that affect products developed by Internet Systems Consortium (ISC), 39.2% are self-published by Internet Systems Consortium (ISC) as a CNA.
Trends Over Time
The number and severity of CVEs published by Internet Systems Consortium (ISC) over time
Top CVEs
All CVEs published by Internet Systems Consortium (ISC) as a CNA, regardless of affected vendor or product.
121 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8617MEDIUM Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG | May 19, 2020 | 5.9 | 85 | NO | YES |
CVE-2021-25216CRITICAL In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9. | Apr 29, 2021 | 9.8 | 76 | NO | NO |
CVE-2020-8625HIGH BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerabl | Feb 17, 2021 | 8.1 | 62 | NO | NO |
CVE-2017-3144HIGH A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool of socket descriptors available to the DHCP server. Affects I | Jan 16, 2019 | 7.5 | 59 | NO | NO |
CVE-2018-5740HIGH "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the | Jan 16, 2019 | 7.5 | 58 | NO | NO |
CVE-2026-3593CRITICAL A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.
This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 thr | May 20, 2026 | 9.8 | 43 | NO | NO |
CVE-2022-3736HIGH BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG quer | Jan 26, 2023 | 7.5 | 43 | NO | NO |
CVE-2026-13321HIGH The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone.
This issue affects BIND 9 versions 9.11.0 through 9.18.50 | Jul 22, 2026 | 8.6 | 40 | NO | NO |
CVE-2017-3145HIGH BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and cr | Jan 16, 2019 | 7.5 | 38 | NO | NO |
CVE-2026-5946HIGH Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that s | May 20, 2026 | 7.5 | 37 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (121 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Internet Systems Consortium (ISC) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Internet Systems Consortium (ISC) as a CNA — matched by CVE ID, not by organization name.