Vulnerability intelligence
CVE-2026-24061
GNU InetUtils Argument Injection Vulnerability
GNU InetUtils
GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.
CVSS Score
—
Unrated
EPSS — Exploit Probability
98%
Riskier than 100% of all CVEs · checked 2026-09-04
Exploitation
Confirmed in the wild
KEV since 2026-01-26
Remediation
Unconfirmed
Federal deadline 2026-02-16
CISA required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2026-02-16.
10 articles across 5 outlets · first covered Jan 22, 2026 · latest Mar 18, 2026
Coverage timeline
-
Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE via Port 23thehackernews.com · Mar 18, 2026
-
83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructurethehackernews.com · Feb 12, 2026
-
Root via Telnet: Why You Must Patch Your Synology NAS Against This Decade-Old Ghostsecurityonline.info · Feb 3, 2026
-
Critical Telnet Server Flaw Exposes Forgotten Attack Surfacewww.darkreading.com · Jan 27, 2026
-
-
Organizations Warned of Exploited Linux Vulnerabilitieswww.securityweek.com · Jan 27, 2026
-
⚡ Weekly Recap: Firewall Flaws, AI-Built Malware, Browser Traps, Critical CVEs & Morethehackernews.com · Jan 26, 2026
-
Security Affairs newsletter Round 560 by Pierluigi Paganini – INTERNATIONAL EDITIONsecurityaffairs.com · Jan 25, 2026
-
11-Year-Old critical telnetd flaw found in GNU InetUtils (CVE-2026-24061)securityaffairs.com · Jan 24, 2026
-
Critical GNU InetUtils telnetd Flaw Lets Attackers Bypass Login and Gain Root Accessthehackernews.com · Jan 22, 2026