Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Internet Systems Consortium

Internet Systems Consortium Vendor Cyber Rating & Cyber Score

isc.org

Internet Systems Consortium, Inc. (ISC) is the custodian and distributor of commercial quality Open Source software for the Internet Community. ISC provides world-class professional services based on our software. Since 1996, ISC has led the industry with the most complete reference standard implementation of DNS software. ISC also provides reference implementations for DHCP. -- If you use BIND DNS or Kea DHCP in your network, find out how you can get a support agreement from ISC - get expert guidance on making the most of your infrastructure. Managed Open Source means that users benefit from community ideas, while quality and compliance are the responsibility of professional software engineers. ISC provides a number of Operational


ISC A.I CyberSecurity Scoring

ISC
Company Information
Website:https://www.isc.org/
Employees number:45
Number of followers:2,641
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:isc.org
ISC Risk Score (AI oriented)
Between 700 and 749
logo
ISCTechnology, Information and Internet
Updated:
04/04/2026
742/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
ISC Global Score (TPRM)
xxxx
logo
ISCTechnology, Information and Internet
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

ISC
ISCModerate
Current Score
742Ba (MODERATE)
01000
3 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
743Before Incident
MAY 2026
742Before Incident
APRIL 2026
742Before Incident
MARCH 2026
747Before Incident
Vulnerability
25 Mar 2026ISC
Internet Systems Consortium: ISC Issues Critical Warning Over Kea DHCP Vulnerability That Could Remotely Crash Services

Critical Kea DHCP Server Vulnerability Exposes Networks to DoS Attacks

742After Incident
CRITICAL-5
INT1774592629
Critical Kea DHCP Server Vulnerability Exposes Networks to DoS Attacks The Internet Systems Consortium (ISC) has issued a high-severity security advisory for a stack overflow vulnerability (CVE-2026-3608) in its Kea DHCP server software, a widely used solution for IP address management in enterprise and ISP networks. Disclosed on March 25, 2026, the flaw carries a CVSS score of 7.5 and could allow unauthenticated remote attackers to crash critical network services, leading to a complete denial-of-service (DoS). The vulnerability stems from improper handling of maliciously crafted messages sent via API sockets or High Availability (HA) listeners, triggering a stack overflow in multiple Kea daemons. Affected components include the control agent (kea-ctrl-agent), dynamic DNS updater (kea-dhcp-ddns), and both IPv4/IPv6 services (kea-dhcp4/kea-dhcp6). Exploitation results in an immediate DHCP service outage, preventing new devices from joining the network and disrupting lease renewals for existing clients. Impacted versions include Kea 2.6.0–2.6.4 and 3.0.0–3.0.2. The flaw was discovered and reported by Ali Norouzi of Keysight. While no active exploits have been observed, the ISC urges administrators to upgrade to patched versions 2.6.5 or 3.0.3 immediately. For those unable to patch, securing API sockets with TLS mutual authentication (via `cert-required: true`) can mitigate the risk by blocking unauthenticated connections.
INCIDENT DETAILS -
TYPE
Denial-of-Service (DoS)
IMPACT
Systems Affected: Kea DHCP server (kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, kea-dhcp6)Downtime: Immediate DHCP service outageOperational Impact: Prevents new devices from joining the network; disrupts lease renewals for existing clients
FEBRUARY 2026
746Before Incident
JANUARY 2026
746Before Incident
DECEMBER 2025
746Before Incident
NOVEMBER 2025
746Before Incident
OCTOBER 2025
745Before Incident
SEPTEMBER 2025
745Before Incident
AUGUST 2025
745Before Incident
JULY 2025
744Before Incident
JUNE 2025
766Before Incident
Vulnerability
16 Jun 2025ISC
Internet Systems Consortium: BIND 9 Vulnerability Allows Attackers to Crash DNS Servers Using Malicious Records

Critical BIND 9 Vulnerability (CVE-2025-13878) Enables Remote DNS Server Crashes

744After Incident
LOW-22
INT1769088576
Critical BIND 9 Vulnerability (CVE-2025-13878) Enables Remote DNS Server Crashes The Internet Systems Consortium (ISC) has disclosed a high-severity vulnerability in BIND 9, tracked as CVE-2025-13878, that allows remote attackers to crash DNS servers by sending malformed BRID (Boundary Router Identifier) and HHIT (Host Identity Tag) records. The flaw causes the named daemon to terminate unexpectedly, resulting in a denial-of-service (DoS) condition. The vulnerability affects multiple BIND 9 release branches, including stable, development, and preview editions. Exploitation requires no authentication or special privileges, making it accessible to any attacker with network access. Both authoritative DNS servers and recursive resolvers are impacted, broadening the potential attack surface. ### Affected Versions & Patches The following BIND 9 versions are vulnerable, with patched releases available: | BIND Edition | Vulnerable Versions | Patched Version | |------------------------|---------------------------------------|----------------------| | BIND 9 Stable | 9.18.40 – 9.18.43 | 9.18.44 | | BIND 9 Stable | 9.20.13 – 9.20.17 | 9.20.18 | | BIND 9 Development | 9.21.12 – 9.21.16 | 9.21.17 | | BIND 9 Preview | 9.18.40-S1 – 9.18.43-S1 | 9.18.44-S1 | | BIND 9 Preview | 9.20.13-S1 – 9.20.17-S1 | 9.20.18-S1 | ### Technical Details - CVE ID: CVE-2025-13878 - Severity: High (CVSS 7.5) - Attack Vector: Network/Remote (no authentication required) - Impact: Availability (DoS), no confidentiality or integrity risks - Disclosure Date: January 21, 2026 The vulnerability was discovered by Vlatko Kosturjak of Marlink Cyber and responsibly disclosed to ISC. While no active exploits have been observed, the ease of exploitation and BIND’s widespread use make this a critical patching priority. ISC has released fixes, and no workarounds exist affected systems must be upgraded immediately.
INCIDENT DETAILS -
TYPE
Denial-of-Service (DoS)
IMPACT
Systems Affected: DNS servers (authoritative and recursive resolvers)Operational Impact: Denial-of-Service (DoS) condition
Vulnerability
16 Jun 2025ISC
Internet Systems Consortium (ISC)

Critical DNS Cache Poisoning Vulnerability in BIND 9 (CVE-2025-40778)

744After Incident
CRITICAL-22
INT3932739102725
A critical DNS cache poisoning vulnerability (CVE-2025-40778, CVSS 8.6) was disclosed in BIND 9, the widely used DNS resolver software maintained by ISC. The flaw, stemming from improper handling of unsolicited DNS resource records, allows off-path attackers to inject forged entries into DNS caches without direct network access. Over 706,000 exposed BIND 9 instances worldwide are affected, including versions 9.11.0–9.16.50, 9.18.0–9.18.39, 9.20.0–9.20.13, and 9.21.0–9.21.12. While no active exploitation has been reported, a public proof-of-concept exploit on GitHub escalates risks, enabling attackers to redirect traffic to malicious destinations, facilitating phishing, data interception, or service disruptions. Poisoned caches could misroute clients for extended periods (hours/days), depending on TTL values. ISC urges immediate patching to versions 9.18.41, 9.20.15, or 9.21.14+, alongside mitigations like DNSSEC validation, recursion restrictions, and cache monitoring. Unpatched systems—especially high-traffic resolvers used by enterprises, ISPs, and governments—face severe exposure, risking widespread internet infrastructure compromise.
INCIDENT DETAILS -
TYPE
VulnerabilityDNS Cache Poisoning
IMPACT
Systems Affected: 706,000+ exposed BIND 9 resolver instances worldwideTraffic redirection to malicious destinationsPhishing attacksData interceptionService disruptionsPotential loss of trust in DNS infrastructureHigh (if traffic redirected to phishing sites)High (if traffic intercepted or redirected)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for ISC ?
?
What was ISC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was ISC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was ISC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was ISC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was ISC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was ISC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was ISC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was ISC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was ISC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was ISC's A.I Rankiteo Cyber Score in August 2025 ?
?
What was ISC's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on ISC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with ISC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view ISC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?