An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a configuration that met the criteria for the vulnerability and if the attacker could cause it to accept a query that possessed the required attributes. Please note: This vulnerability affects the "nxdomain-redirect" feature, which is one of two methods of handling NXDOMAIN redirection, and is only available in certain versions of BIND. Redirection using zones of type "redirect" is not affected by this vulnerability. Affects BIND 9.9.8-S1 -> 9.9.8-S3, 9.9.9-S1 -> 9.9.9-S6, 9.11.0-9.11.0-P1.
Conclusion & alert: CVE-2016-9778 is rated High Risk (68.5/100): CVSS High severity, with high exploitation likelihood (EPSS 12.00%, 96th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +6.58% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 5.42% | 12.00% | +6.58% |
| 2 | 2026-04-15 | 6.61% | 5.42% | -1.19% |
| 3 | 2026-02-03 | — | 6.61% | — |
Full EPSS history (18 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.0 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.9 | 3.0 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2016-9778 unimportant priority: Debian including 1 source packages (bind9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2016-9778 |
gentoo
|
normal | CVE-2016-9778: 1 GLSA(s) (201708-01), 1 atom(s) (net-dns/bind); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2016-9778 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2016-9778 |
suse
|
high | CVE-2016-9778 severity important: SUSE including 365 source package names (amazon/suse-sles-15-sp1-chost-byos-v20210304-hvm-ssd-x86_64, amazon/suse-sles-15-sp1-chost-byos-v20220127-hvm-ssd-x86_64, …), 486 product×package rows across 34 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 6, … (34 product lines)): Fixed 207, Known Affected 157, Known Not Affected 122. | https://www.suse.com/security/cve/CVE-2016-9778/ |
ubuntu
|
medium | CVE-2016-9778 medium priority: Ubuntu including 1 source packages (bind9), 5 status rows across 5 suites (precise, trusty, upstream, xenial, yakkety): not-affected 4, needs-triage 1. | https://ubuntu.com/security/CVE-2016-9778 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| isc | bind | 9.9.8 | cpe:2.3:a:isc:bind:9.9.8:s1:*:*:*:*:*:* |
| isc | bind | 9.9.8 | cpe:2.3:a:isc:bind:9.9.8:s2:*:*:*:*:*:* |
| isc | bind | 9.9.8 | cpe:2.3:a:isc:bind:9.9.8:s3:*:*:*:*:*:* |
| isc | bind | 9.9.9 | cpe:2.3:a:isc:bind:9.9.9:s1:*:*:*:*:*:* |
| isc | bind | 9.9.9 | cpe:2.3:a:isc:bind:9.9.9:s6:*:*:*:*:*:* |
| isc | bind | 9.11.0 | cpe:2.3:a:isc:bind:9.11.0:*:*:*:*:*:*:* |
| isc | bind | 9.11.0 | cpe:2.3:a:isc:bind:9.11.0:p1:*:*:*:*:*:* |
| netapp | data_ontap_edge | — | cpe:2.3:a:netapp:data_ontap_edge:-:*:*:*:*:*:*:* |
| netapp | solidfire_element_os_management_node | — | cpe:2.3:a:netapp:solidfire_element_os_management_node:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/95388 | Third Party Advisory VDB Entry |
| http://www.securitytracker.com/id/1037582 | Third Party Advisory VDB Entry |
| https://kb.isc.org/article/AA-01442/ | Vendor Advisory |
| https://security.gentoo.org/glsa/201708-01 | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20180926-0005/ | Third Party Advisory |