Story perspectives
Critical DNS Vulnerabilities Discovered, Patches Released
10/23/2025
26 5
1 of 1
Story summary
- BIND has identified two critical vulnerabilities, CVE-2025-40778 and CVE-2025-40780, with severity 8.6, that could corrupt DNS caches and redirect users to malicious sites.
- A related issue in the Unbound software has a severity rating of 5.6.
- Patches for these vulnerabilities were released on Wednesday.
- The situation echoes the 2008 DNS cache poisoning attack, which prompted a coordinated industry response to enhance security.
