Warning: Critical Authentication Bypass in GNU INETUTILS TELNETD! Patch Immediately!
ID: 1d9d62fd-84e4-5224-9e1d-d5f45b810d41
STIX ID: report--1d9d62fd-84e4-5224-9e1d-d5f45b810d41
Feed Name: CCB Advisories Feed
**CVE-2026-24061 (GNU Inetutils telnetd) — Critical authentication bypass with active exploitation reported.** An argument-injection flaw in telnetd allows unauthenticated attackers to set USER to "-f root" and bypass authentication to obtain remote root access (CVSS 9.8); CISA has added it to the Known Exploited Vulnerabilities catalog. Recommended mitigations include disabling telnet, applying vendor/OS patches as soon as possible, restricting network exposure (firewalls/VPN/ZNTA), and increasing monitoring for related suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
