logo

800K+ Telnet Servers Exposed to RCE Attacks – PoC Released

ID: f1b9c07e-8cd0-55a9-802b-f929a25cd440

STIX ID: report--f1b9c07e-8cd0-55a9-802b-f929a25cd440

Feed Name: cybersecurityNews.com

Threat Score
92/100

Date Published: 2026-01-26

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Critical Telnetd Authentication Bypass (CVE-2026-24061):** A high-severity argument injection flaw in GNU Inetutils telnetd (v1.9.3–2.7) allows attackers to set USER to "-f root" and bypass authentication to gain root RCE; proof-of-concept exploits are public and widespread scanning/exploitation was observed shortly after disclosure, affecting roughly 800,000 internet-exposed Telnet instances and prompting immediate upgrade or mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.