CISA added CVE-2015-5477 to its Known Exploited Vulnerabilities (KEV) catalog on 2026-10-08. The flaw dates from 2015 and affects ISC BIND. A remote attacker with no credentials can crash the named DNS daemon by sending TKEY queries.
What Is It
CVE-2015-5477 is a denial-of-service vulnerability in named, the server daemon in ISC BIND. According to NVD, remote attackers can send TKEY queries that trigger a REQUIRE assertion failure, and the failure makes the daemon exit. CISA lists the flaw as "ISC BIND Data Processing Errors Vulnerability" (CWE-19). A secondary CNA assessment maps it to CWE-617 (Reachable Assertion). NVD first published the CVE on 2015-07-29.
Why It Matters
- Active exploitation confirmed: CISA added the flaw to KEV on 2026-10-08. The CISA Coordinator SSVC assessment rates exploitation as active and the flaw as automatable.
- Severity: The CVSS 3.1 base score is 7.5 (HIGH), with vector
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The attack works over the network, has low complexity and needs no privileges or user interaction. It affects availability only. - Short federal deadline: The KEV due date is 2026-10-11, three days after the flaw was added. Under BOD 26-04, this deadline is binding on U.S. federal civilian executive branch agencies. Other organizations aren't bound by it, but CISA encourages them to use the KEV catalog to set their own remediation priorities.
- Ransomware use: KEV lists known ransomware campaign use as "Unknown."
- Broad reach: CISA notes the flaw could affect an open-source component, library, protocol or proprietary implementation used by different products. Vendor references include Juniper and Red Hat.
What's Vulnerable
NVD lists these affected versions:
- ISC BIND 9.x before 9.9.7-P2
- ISC BIND 9.10.x before 9.10.2-P3
Products that bundle BIND may also be affected. Juniper published a Junos security bulletin for this CVE, and Red Hat, Debian and Ubuntu issued advisories.
Patch Status
ISC's advisory AA-01272 is tagged as a patch and vendor advisory. Per NVD, the fixed releases are BIND 9.9.7-P2 and 9.10.2-P3.
For agencies covered by BOD 26-04 (Prioritizing Security Updates Based on Risk), CISA's required action is to apply mitigations according to vendor instructions and to follow CISA's Forensics Triage Requirements. If no mitigations are available, the directive tells these agencies to follow the BOD 26-04 guidance for cloud services or stop using the product. Covered agencies must also assess each asset's internet exposure. KEV marks forensic triage for this entry as "No." These requirements apply to federal agencies only, but other organizations can use them as a model for their own response.
Organizations still running these BIND versions, whether directly or inside appliances and distributions, should apply vendor or distribution updates promptly. Federal agencies covered by BOD 26-04 must do so by 2026-10-11. Other organizations can use that date as a benchmark, especially for internet-facing resolvers and authoritative servers.