ISC BIND Data Processing Errors Vulnerability (CVE-2015-5477) is being actively exploited, CISA warns
CISA lists this as exploited in the wild. Unpatched BIND systems are exposed to active attacks now.
Apply the vendor's security update for BIND.
ISC BIND Data Processing Errors Vulnerability
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog: attackers are using it. If you run BIND, fix it now.
CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
US federal civilian agencies must remediate by Oct 11, 2026.
Official fix available since
Apply the vendor's update to every affected system. Check the fixed-in versions below where known.
Basis: NVD patch reference
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.
| Product | Vendor | Affected versions | Source |
|---|---|---|---|
| BIND | ISC | <= 9.9.7; <= 9.10.2 | KEV |
Sources: KEV = CISA Known Exploited Vulnerabilities catalog.
Developments from the last 30 days, newest first.
CVE-2015-5477 scored CVSS 7.8: ISC BIND, ISC BIND Data Processing Errors Vulnerability
CISA lists this as exploited in the wild. Unpatched BIND systems are exposed to active attacks now.
Basis: NIST National Vulnerability Database
Patch released for CVE-2015-5477: ISC BIND, ISC BIND Data Processing Errors Vulnerability
An official fix is now available for ISC BIND. This vulnerability is being exploited, so apply it promptly.
Basis: NVD patch reference
CVE-2015-5477 added to CISA KEV: ISC BIND, ISC BIND Data Processing Errors Vulnerability
CISA lists this as exploited in the wild. Unpatched BIND systems are exposed to active attacks now.
Basis: CISA Known Exploited Vulnerabilities catalog
CISA lists this as exploited in the wild. Unpatched BIND systems are exposed to active attacks now.
Apply the vendor's security update for BIND.
CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched Exchange Server and Struts systems are exposed to active attacks now.
Treat this as an emergency.