Review reviewHigh
CVE-2026-33612
PowerDNS Recursor
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.
- CVSS
- 7.5
- EPSS
- 0.11% 1.81% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.25
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.
The CVSS severity warrants an early asset and exposure review.
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.
Confirm exposure before applying a vendor-supported change.
Confirm that PowerDNS Recursor and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.