logo

Warning: Critical Authentication Bypass in GNU INETUTILS TELNETD! Patch Immediately!

ID: 1d9d62fd-84e4-5224-9e1d-d5f45b810d41

STIX ID: report--1d9d62fd-84e4-5224-9e1d-d5f45b810d41

Feed Name: CCB Advisories Feed

Threat Score
95/100

Date Published: 2026-01-27

Date Updated: 2026-07-24

...
...

**CVE-2026-24061 (GNU Inetutils telnetd) — Critical authentication bypass with active exploitation reported.** An argument-injection flaw in telnetd allows unauthenticated attackers to set USER to "-f root" and bypass authentication to obtain remote root access (CVSS 9.8); CISA has added it to the Known Exploited Vulnerabilities catalog. Recommended mitigations include disabling telnet, applying vendor/OS patches as soon as possible, restricting network exposure (firewalls/VPN/ZNTA), and increasing monitoring for related suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.