CVE-2026-19033 applies IXFR deltas to the live zone before TSIG verification. The disclosure describes the IXFR update as unauthenticated.
CVE-2026-19666 is a use-after-free in query_addnoqnameproof() through the DNS64 filter64 path. Deployments not using that path are not identified by the disclosure as having this specific trigger.
CVE-2026-19662 is described as a qpcache NOQNAME proof use-after-free that crashes the recursive resolver. This is the vulnerability in the disclosed details that explicitly names recursive resolver functionality.
Yes. CVE-2026-76163 causes named to abort on a TKEY query when the user configuration has no global options statement. Checking whether a global options statement is present can identify this stated condition.
CVE-2026-19662 can crash a recursive resolver, CVE-2026-19667 causes a remote assertion failure, CVE-2026-19668 causes resource exhaustion from excessive DNSSEC cryptographic material matching, CVE-2026-75029 enables wire-to-work amplification, and CVE-2026-76163 can abort named.