Updated bind packages fix security vulnerabilities: Incorrect acceptance of NSEC3 records. (CVE-2026-10723) Key Record using PRIVATEDNS algorithm may lead to unexpected exit. (CVE-2026-10822) Potential wildcard CNAME RPZ policy bypass. (CVE-2026-11331) Unnecessary validation of DNSSEC signed records. (CVE-2026-11605) Cache poisoning possible with label count discrepancy, RRSIG, and wildcards. (CVE-2026-11721) Record ordering based unexpected exit with CNAME or DNAME. (CVE-2026-12617) Unexpected exit in certain situations with NSEC and NSEC3 both present. (CVE-2026-13204) DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field. (CVE-2026-13321)