ALMC
ALMC Security Logo - Mantenimiento Web, Programación Web Barcelona, Servidores Barcelona, Ciberseguridad Barcelona
  • English
    Español English Français Català

Quick search

Results without leaving the page.

Type to search ALMC products, services, articles and tools.

View all results
Habla a nuestro AgenteIA · respuestas al instante · 24/7
  • HomeALMC
  • ALMCAbout Us
  • ALMC SECURITY S.L.U.Contact
  • Posts
    • Posts
    • Categorías
    • Etiquetas
    • Estados
  • Soluciones
    • Desarrollo Web en Lleida — Diseño a Medida que Vende
    • Tienda Online a Medida — E-commerce que Vende de Verdad
    • Chatbot IA para Empresas — Automatiza tu Atención al Cliente
    • Automatización de Procesos para Empresas — Menos Tareas, Más Resultados
    • Desarrollo de Apps Móviles — iOS y Android a Medida
  • Services
    • Cybersecurity
      • Security Audits and Pentesting
      • Monitoring & Incident Response (SIEM)
      • System & Server Hardening
      • Compliance Consulting (GDPR, ENS, ISO 27001)
      • Cloud Security (AWS, Azure, Google Cloud)
    • Programming
      • Full Stack Web Development Laravel, Vue.js
      • Process Automation (Scripts and Bots)
      • Process Automation Scripts and Bots
      • API Integrations & Microservices
      • Code Maintenance and Optimization
    • Servers
      • Server Management & Monitoring
      • Cloud Migration (AWS, Azure, Google Cloud)
      • Performance Optimization
      • Virtualization & Containers (Docker, Kubernetes)
      • Backup & Disaster Recovery Plans
    • Repair Hacked Website
    • Website Maintenance
      • WordPress Maintenance
      • PrestaShop Maintenance
      • Magento Maintenance
      • Joomla Maintenance
      • Drupal Maintenance
      • Shopify Maintenance
      • Wix Maintenance
      • Concrete5 Maintenance
      • HTML Maintenance
      • PHP Maintenance
      • JavaScript Maintenance
      • Python Maintenance
    • Website Repair
      • Hacked site cleanup
      • Fix WordPress
      • Fix PrestaShop
      • Fix Magento
      • Fix Joomla
      • Fix Drupal
      • Fix Shopify
      • Fix OpenCart
      • Fix Moodle
  • Industries
    • 3D Printing & Additive
    • Accounting
    • Advertising & Marketing
    • Aerospace & Defense
    • Agriculture
    • Architecture & Engineering
    • Arts & Culture
    • Automotive
    • Banking & Finance
    • Biomedical Research
    • Biotechnology
    • Breweries
    • Call Centers & BPO
    • Chemicals
    • Cleaning Services
    • Clinics
    • Cloud Providers
    • Construction
    • Consulting
    • Cosmetics & Beauty
    • Courier & Last Mile
    • Cybersecurity
    • Data Centers
    • Defense & Security
    • E-Commerce
    • EdTech
    • Education (K-12)
    • Electrical Equipment
    • Electronics
    • Environmental NGOs
    • Environmental Services
    • Events & Conferences
    • Facilities Management
    • Fashion & Luxury
    • FinTech
    • Fishing & Aquaculture
    • Food & Beverage Manufacturing
    • Forestry
    • Freight Transport
    • Furniture
    • Gaming
    • Government & Public Administration
    • GovTech
    • Gyms & Fitness Centers
    • Healthcare Providers
    • HealthTech
    • Higher Education
    • Home Appliances
    • Home Services
    • Hospitality
    • Hospitals
    • Human Resources
    • Insurance
    • InsurTech
    • Internet & Web Services
    • Investment & Asset Management
    • IT Services
    • Jewelry
    • Landscaping & Gardening
    • Legal Services
    • Logistics & Supply Chain
    • Machinery
    • Maritime
    • Media & Entertainment
    • Medical Devices
    • Metals
    • Mining
    • Music Industry
    • Nonprofit & NGOs
    • Oil & Gas
    • Paper & Print Media
    • Paper & Pulp
    • Pharmaceuticals
    • Photography & Video
    • Plastics
    • Postal & Courier
    • Printing
    • Private Education & Academies
    • Property Development
    • Property Management
    • PropTech
    • Public Safety & Emergency
    • Publishing
    • Rail & Public Transport
    • Real Estate
    • Real Estate Agencies
    • Religious Organizations
    • Renewable Energy
    • Research & Development
    • Research Labs
    • Restaurants & Food Service
    • Retail
    • Security Services
    • Semiconductors
    • Software Development
    • Sports & Fitness
    • Sports Clubs
    • Staffing & Recruitment
    • Telecommunications
    • Textile & Apparel
    • Tobacco
    • Toys
    • Travel & Tourism
    • Travel Agencies
    • Utilities
    • Veterinary & Animal Care
    • Warehousing
    • Waste Management
    • Water Treatment
    • Wholesale
    • Wineries & Vineyards
  • Tools
    • Network
      • What's my IP
      • WHOIS IP
      • Domain WHOIS
      • Geolocate IP
      • DNS Lookup
      • DNS Propagation
      • ASN Lookup
      • Reverse Lookup
      • Domain monitoring
    • Image Compressor
    • MCP Servers
  • Products
    • Whatsboost
      • Whatsboost PrestaShop
      • Whatsboost WordPress
      • Whatsboost Shopify
    • Ulix
      • Extension QR para navegador
    • Chatbot
      • Chatbot WhatsApp
      • Chatbot Instagram
      • Chatbot Facebook
      • Chatbot TikTok
    • VeriFactu
    • Web TV
      • Mis pantallas
      • Vincular nueva TV
      • Dispositivos vinculados
      • Releases APK
      • Pantallas por cliente
    • Control de Fichajes

5 News at ALMC
  • Inauguration of the... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Inauguration of the...It was a very busy and special day. 30 Jun 2025
  • Website Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    WebsiteI recover the domain I had in the past and set up... 01 Jun 2025
  • Signing of the Lease... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    Signing of the Lease...After spending some time looking for premises, my... 01 Jun 2025
  • ALMC returns and com... Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    ALMC returns and com...We reactivate the brand with ALMC SECURITY SL (CIF... 23 Apr 2025
  • feb. 2025 Web Maintenance, Web Development Barcelona, Servers Barcelona, Cybersecurity Barcelona
    feb. 2025The decision to start entrepreneurship again was b... 01 Feb 2025

View all news

Unbound 1.26.1: Critical DNSSEC Flaw and Server Defence

  1. Home
  2. Blog
  3. Categories
  4. Cybersecurity
  5. Unbound 1.26.1: Critical DNSSEC Flaw and Serv...
  • All articles
  • Categories
  • Tags
  • Statuses

Unbound 1.26.1: Critical DNSSEC Flaw and Server Defence

A critical DNS resolver flaw you cannot ignoreIf your infrastructure runs Unbound as a DNS resolver, the release of version 1.26.1 deserves your immed...

A critical DNS resolver flaw you cannot ignore

If your infrastructure runs Unbound as a DNS resolver, the release of version 1.26.1 deserves your immediate attention. NLnet Labs has fixed CVE-2026-81642, a critical vulnerability in the DNSSEC validator that can crash the service and, under certain conditions, allow remote code execution. The flaw affects every version up to and including 1.26.0, which is a broad range for a component that sits quietly inside many corporate networks, hosting platforms and internal service meshes.

A cracked DNS resolver appliance with malicious packets caught by a protective mesh grille

The issue lives in the DNSSEC validation path when processing DNSKEY records. A buffer overflow can occur while handling data arriving from DNS responses. Because that traffic comes in over the network and the resolver process runs continuously, the exposure is not theoretical. The manufacturer has assigned a CVSS 4.0 score of 9.1, with a network vector, no privileges required and no user interaction. That profile is typical of defects that should be closed as soon as possible.

How the attack works and who is at risk

Exploitation requires an adversary to control a malicious DNS zone and to make the vulnerable resolver query it. This can happen if the resolver accepts queries from untrusted networks, resolves for external users, or if an attacker can induce queries towards their domain. In the worst case, the manipulated input does not only cause denial of service; it also leaves open the possibility of RCE through attacker-controlled data. At the time of disclosure, there was no public active exploitation in real attacks, but that is no reason to delay patching.

Organisations in Barcelona, Lleida, Tarragona and Girona that run their own resolvers for internal services, VPNs, hosting panels or customer-facing DNS should treat this as a priority. The same applies to managed service providers and SMEs with on-premise servers, where a single Unbound instance may support authentication, mail filtering, monitoring or application backends.

What Unbound 1.26.1 actually fixes

The new release adds a proper buffer capacity check after decompression and before writing, a critical point to prevent data from overrunning memory limits. The same launch bundles eight other security fixes, including CVE-2026-82717, a heap corruption when synthesising CNAME records, and CVE-2026-81634, a possible heap overflow during DNSSEC canonicalisation. Together, the package not only aims to prevent crashes but also to reduce attack surfaces that could degrade service or lead to unexpected behaviour.

The operational recommendation is straightforward: update to Unbound 1.26.1. If a maintenance window does not allow immediate adoption, apply the official patch for CVE-2026-81642 to the source tree with patch -p1, recompile and install, then plan the full set of corrections as soon as possible. It is also worth inventorying Unbound instances embedded in appliances, containers or distribution packages, because it is not always obvious which version is actually running and whether it includes the equivalent fix.

Beyond the patch: reducing your exposure

Patching is necessary but not sufficient. A resolver that is reachable from untrusted networks will always be a target. Restrict recursive queries to known client networks, disable open recursion, and segment DNS services from general-purpose workloads. Monitor resolver logs for repeated query failures, unusual DNSKEY lookups or sudden process restarts, which can be early signs of probing.

This is where a centralised approach to server protection pays off. Instead of configuring firewall rules and intrusion prevention separately on every machine, Abuse Shield from ALMC.es centralises protection across your servers: automatic blocking of malicious IPs, managed fail2ban across multiple machines, and a shared reputation feed between all your servers. When one node detects abusive behaviour, the rest learn from it. That shared intelligence is especially valuable for DNS infrastructure, where a single hostile zone or scanning source can affect several resolvers at once.

A practical checklist for sysadmins

  • Identify every Unbound instance, including those inside containers, appliances and distribution packages.
  • Upgrade to 1.26.1 or apply the official patch and recompile if you cannot upgrade immediately.
  • Verify the running version after the update, not just the package version.
  • Restrict recursion to trusted networks and review firewall rules for port 53.
  • Enable logging and alerting for resolver crashes, restarts and unusual query patterns.
  • Centralise IP blocking and fail2ban management so that a threat seen on one server protects the rest.
  • Document the patch status and review it periodically, in line with GDPR and internal security policies.

DNS is one of those services that only gets noticed when it fails. A critical flaw in its validation logic is a reminder that infrastructure security is a continuous process, not a one-off task. Patch Unbound, review your exposure, and consider whether your current server protection model can react quickly enough when the next CVE arrives.

Related

  • How to Harden Your Servers with Fail2ban and IP Reputation Feeds
  • Fail2ban: Your First Line of Defense Against Unauthorized Server Access
  • Critical libssh2 flaw: urgent patch for SSH servers
  • Desarrollo web

Put these ideas into practice

Talk to ALMC about a solution for your business. Explore your options or contact our team.

Soluciones ALMC

Cloud Security (AWS, Azure, Google Cloud)
Virtualization & Containers (Docker, Kubernetes)
System & Server Hardening
API Integrations & Microservices
Full Stack Web Development Laravel, Vue.js
Relacionados
  • Cisco ISE Zero-Day: Why Patch Now and Harden After
    Cybersecurity · 1 day ago
  • WooCommerce Plugin Flaw: Web Shells and Server Defence
    Cybersecurity · 2 days ago
  • OAuth Token Leak: Supply Chain Lessons for Server Security
    Cybersecurity · 4 days ago
  • Browser Extensions Are a Supply Chain Risk: Lessons from the Twitch OAuth Leak
    Cybersecurity · 4 days ago
  • Browser Extension Leaks OAuth Tokens: Lessons for Server Security
    Cybersecurity · 4 days ago
  • Artifactory Under Siege: Lessons for Server Security
    Cybersecurity · 1 week ago
Servidores MCP Destacados
  • MCP Invoice Parser
    Productivity
  • MCP Snowflake Reader
    Database
  • PyGithub MCP Server
    Version Control
  • A11y MCP Server
    Development
  • Test Automator
    Development
  • AI Agent Playwright
    Development
  • iMCP
    Productivity
  • Volatility3 MCP Server
    Development
  • YouTube
    Search
Ver todos los servidores MCP
Cybersecurity · Blog Brain · 2026-09-19
Cerrar panel
Your ecosystem

SaaS applications

Open each workspace directly with your ALMC account.

My account Create account
VeriFactuVerified invoicingAbuse ShieldWeb securityWhatsBoostSales and CRMCommerceStore and POSEmail AISmart emailWebTVDigital signageTime trackingWorking-time controlPrintFlowPrint workflows
Agente Smith · ALMCAgente IA propio on-premise

Hola 👋 Soy Smith, el agente IA de ALMC. Pregúntame sobre ciberseguridad, IA, desarrollo a medida o nuestros productos SaaS.

¿Prefieres hablar con persona? Contacto humano

ALMC access centre

One account · All your services

Start wherever you want.

Create an account to centralise your services, or ask for guidance if you do not know what you need yet.

Create account Talk to ALMC

Explore by product

VeriFactuInvoicingAbuse ShieldSecurityWhatsBoostSalesCommerceStore and POSEmail AIAutomationWebTVDigital signage

Sign in to your account.

The same sign-in brings together your services, team and billing.

Enter my panelAccess your services, team and billing.
Sign in

Not a client yet? Create an account

ALMC Security Logo

Experts in cybersecurity, custom Laravel development, and server management. We deliver robust, secure, and personalized technological solutions.

Latest News

Inauguration of the first office in Lleida of ALMC SECURITY SL
Inauguration of the first office in Lleida of ALMC...
30 Jun 2025
Website
01 Jun 2025
Signing of the Lease Contract
Signing of the Lease Contract
01 Jun 2025

Main Services

  • desarrollo web lleida
  • tienda online a medida
  • chatbot ia empresa
  • automatización procesos empresa
  • desarrollo aplicaciones móviles

Suite SaaS

  • PrintFlow (copisterías)
  • WebTV (cartelería)
  • VeriFactu (facturación)
  • Fichaje horario

Contact

  • Rambla de Ferran, 37, 25007 Lleida

  • +34 614 443 757

  • info@almc.es

Follow Us

Useful links

  • About us
  • Contact
  • Reserva cita
  • Hacked website repair
  • Website maintenance
  • Website repair
  • Tools
  • What is my IP
  • Compress images
  • Site search
  • Blog

© Copyright 2026. ALMC SECURITY S.L.U.

  • Legal
      • Privacy Policy
      • Terms and Conditions of Service
      • Legal Notice and Corporate Information
      • Cookie Policy
  • Resources
    • Blog
    • Sitemap

ALMC

Legal

This site only uses first-party cookies and local browser storage, and only to make it work: keeping your session, protecting forms, remembering your language and not showing you this notice again. We use no analytics or advertising cookies, there are no third-party cookies and we do not build profiles. As strictly necessary technical cookies, they are exempt from consent under Article 22.2 of the Spanish LSSI-CE: this notice is informative and the button only stops it from appearing again. You can delete or block them from your browser, though some features may then stop working. Cookie Policy · Privacy Policy.

Chat now
Call Sales
+34 614 443 757

More ways to contact us

¿Hablamos directamente?

Reserva una cita en mi agenda — yo te llamo o nos vemos por Google Meet

  • ✓Confirmación instantánea por WhatsApp
  • ✓Disponibilidad en tiempo real
  • ✓Recordatorio 1h antes
  • ✓Cancela o cambia hora con un click
Initial consultation · 30min
📅 Ver disponibilidad y reservar