logo

Nearly 800,000 Telnet servers exposed to remote attacks

ID: f0b5b5c1-a572-56f4-a63a-0ced0b66a913

STIX ID: report--f0b5b5c1-a572-56f4-a63a-0ced0b66a913

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-01-26

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A critical authentication-bypass flaw (CVE-2026-24061) in GNU InetUtils telnetd — patched in version 2.8 — lets attackers bypass login and obtain root by sending a crafted USER environment value (e.g., "-f root") via Telnet option negotiation; Shadowserver reports ~800,000 publicly exposed Telnet instances worldwide and GreyNoise observed limited active exploitation from multiple IPs that attempted post-exploitation Python malware deployment, so administrators should patch, disable telnetd, or block TCP/23 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.