Fixes several security issues:
- CVE-2026-11331 Fix handling of rpz CNAME expansion that returns name too long.
- CVE-2026-11721 Invalid signed wildcard records were being accepted.
- CVE-2026-13321 Fix DNSSEC validation bypass via out-of-zone NSEC Next Field.
- CVE-2026-10723 Correct verification of NSEC3 signer name.
- CVE-2026-12617 Do no assert for some specifics CNAME and DNAME queries.
- CVE-2026-10822 Malformed DNSKEY records could trigger an assertion.
- CVE-2026-11605 Prevent excessive validation work from crafted negative responses.
- CVE-2026-11622 Prevent cache exhaustion under sustained attack.
Full release notes are available upstream at
https://ftp.isc.org/isc/bind9/9.20.26/doc/arm/html/changelog.html