A decade-old BIND flaw just landed on CISA's actively-exploited list — here's what that does and doesn't mean
CVE-2015-5477 is ten years old, but it's now officially flagged as exploited in the wild; the catch is working out who still has anything exposed to it.
What’s actually confirmed
CISA has added CVE-2015-5477, a vulnerability in ISC’s BIND DNS software, to its Known Exploited Vulnerabilities (KEV) catalogue, with the entry dated 8 October 2026. US federal civilian agencies have been given until 11 October 2026 to apply mitigations. CISA’s listing states plainly that exploitation of this bug is confirmed rather than theoretical — the KEV catalogue only exists for vulnerabilities the agency has evidence are being used in real attacks, not ones that merely look dangerous on paper.
That’s the hard part of the story. CVE-2015-5477 itself is logged at NVD and sits in the broader CISA KEV catalogue, where it now shares a list with hundreds of other vendor flaws, from Joomla to 7-Zip to Rockwell industrial controllers.
So what does the bug actually do?
Here’s where we have to be careful: the material CISA has published alongside this entry doesn’t spell out the mechanics of the flaw, beyond confirming it’s a BIND issue from ISC and recommending agencies “apply mitigations in accordance with vendor instructions.” For the technical nuts and bolts — exactly what an attacker sends, and what BIND does wrong when it receives it — you’d need to go to ISC’s own advisory or dig into the full NVD record, neither of which was available to us in detail here. We’re not going to guess at mechanics we can’t verify.
What we can say with confidence is that BIND is one of the most widely deployed DNS server packages on the internet, used by ISPs, universities, hosting providers and plenty of corporate networks to resolve domain names. It is not something that sits on a home router or a personal laptop in any form an ordinary user would recognise or configure.
Who’s actually at risk — and why the date is odd
This is a 2015-vintage vulnerability, meaning it has existed in public records, and presumably had patches available, for roughly a decade. Its reappearance on CISA’s actively-exploited list more than ten years later is notable in itself: it suggests either a fresh wave of attacks against unpatched, ageing BIND installs, or exploitation activity that CISA has only recently gathered sufficient evidence to confirm. The source material doesn’t tell us which, nor does it give a sense of scale — how many servers, which sectors, or whether this is a handful of incidents or something broader.
The people genuinely exposed here are organisations still running old, unpatched BIND servers as part of their DNS infrastructure — think network administrators, not everyday users browsing the web or playing games. If you’ve never heard of BIND and don’t manage a DNS server, this isn’t something that touches you directly.
What to do about it
If you run BIND, or you’re responsible for infrastructure that might, the message is unambiguous: patch now, following ISC’s own guidance, and don’t assume a decade-old CVE is irrelevant just because of its age. CISA’s federal deadline of 11 October 2026 is a compliance requirement for US government agencies specifically, but the same advice applies sensibly to anyone else running exposed BIND instances.
For everyone else, this is infrastructure plumbing, not a reason to change anything about how you use the internet day to day — just a reminder that old software bugs don’t retire themselves.