Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Internet Systems Consortium (ISC)

First CVE: Dec 4, 1996Active for: 30 yearsTotal CVEs: 245
55.0
VTI Score
TOP TARGET

The Internet Systems Consortium develops a focused but foundational set of infrastructure software: BIND (DNS), DHCP and its successor Kea, and INN (news distribution), all of which are deeply embedded in internet-critical services and present across authoritative nameservers, enterprise networks, and service provider infrastructure. Despite this narrow product count, the vendor's vulnerability footprint is substantial and highly prominent in the landscape, reflecting the universal deployment and long operational lifespans of its core products. The exposure recurs through weakness classes centered on input validation, memory-safety issues including buffer-bounds violations and reachable assertions, and protocol-parsing edge cases that are characteristic of systems software handling untrusted network data. Vulnerabilities affecting this vendor frequently acquire public exploit code, making patches operationally urgent even where severity bands vary. Defenders should maintain close tracking of ISC's advisories and treat BIND and DHCP updates as high-priority across DNS and network infrastructure; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
245
Total CVEs
More Total CVEs than 100% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Internet Systems Consortium (ISC) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 4, 1996
29 years ago
Most Recent CVE
May 20, 2026
66 days ago

Self-Reporting Analysis

Of all the CVEs published by Internet Systems Consortium (ISC) as a CNA, 79.3% affect products that Internet Systems Consortium (ISC) develops as a vendor.

79.3%
20.7%
Self-reported: 96 (79.3%)
Third-party: 25 (20.7%)

Of all the CVEs published that affect products developed by Internet Systems Consortium (ISC), 39.2% are self-published by Internet Systems Consortium (ISC) as a CNA.

39.2%
60.8%
Self-published: 96 (39.2%)
Other CNAs: 149 (60.8%)

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (245 CVEs).

245 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-2776HIGH
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause
Sep 28, 20167.587NOYES
CVE-2015-5477HIGH
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
Jul 29, 20157.887NOYES
CVE-2008-1447MEDIUM
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; an
Jul 8, 20086.887NOYES
CVE-2020-8617MEDIUM
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG
May 19, 20205.985NOYES
CVE-2023-50387HIGH
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D
Feb 14, 20247.578NONO
CVE-2010-2156MEDIUM
ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.
Jun 7, 20105.077NOYES
CVE-2021-25216CRITICAL
In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.
Apr 29, 20219.876NONO
CVE-2023-50868HIGH
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-
Feb 14, 20247.572NONO
CVE-2011-0997HIGH
dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell m
Apr 8, 20117.572NONO
CVE-2020-8625HIGH
BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerabl
Feb 17, 20218.162NONO
View all 245 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products245 CVEs
42%
53%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (2.0%)
Network110 (44.9%)
Unknown123 (50.2%)
Physical0 (0.0%)
Adjacent Network7 (2.9%)
Attack Complexity
Low101 (41.2%)
High21 (8.6%)
Unknown123 (50.2%)
User Interaction
None122 (49.8%)
Unknown123 (50.2%)
Required0 (0.0%)
Privileges Required
Low14 (5.7%)
High4 (1.6%)
None104 (42.4%)
Unknown123 (50.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (245 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
6 CVEs
2.4% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
23 CVEs
9.4% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Internet Systems Consortium (ISC).

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Internet Systems Consortium (ISC) — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Internet Systems Consortium (ISC)'s Products

View all 7 CNAs →

Top CWEs