Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
2026-09-17T19:24:00Z•939b0b01bac69c25dbf298d63f4769d60f9f6dd9c8d4388600c24041ef723ea3
CVE-2026-5430CVE-2026-58704CVE-2026-76460CVE-2026-81642CVE-2026-87886CVE-2026-89026AI securityBINDCisco ISEDDoSDNSIssabelUnboundWSO2 API ManagerWooCommerceWordPressactive exploitationauthentication bypassbackdoorcredential theftdata breachmalwarephishingprivilege escalationransomwareremote code executionsupply-chain compromisewiperzero-day
What happened
The feed highlights multiple active and critical security threats, including exploited zero-days, unauthenticated remote code execution, authentication bypasses, malware campaigns, supply-chain compromise, and major data exposure. Highest-priority items include active exploitation of Cisco ISE authentication bypass (CVE-2026-76460), Issabel Framework command execution (CVE-2026-89026), WSO2 API Manager JWT bypass (CVE-2026-5430), WooCommerce web-shell upload flaws, and other vulnerabilities affecting Unbound DNS, BIND, Pixel devices, Acronis cPanel, and Parallels Desktop. The reporting also1
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 939b0b01bac69c25dbf298d63f4769d60f9f6dd9c8d4388600c24041ef723ea3
- Enrichment time
- 2026-09-17T19:24:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.