logo

Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE via Port 23

ID: ee920fcc-8bca-52b8-9525-60fb319a7c16

STIX ID: report--ee920fcc-8bca-52b8-9525-60fb319a7c16

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-03-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A critical pre-auth remote code execution vulnerability (CVE-2026-32746, CVSS 9.8) has been disclosed in GNU InetUtils telnetd (<= 2.7); an attacker can trigger an out-of-bounds write during Telnet LINEMODE SLC option negotiation to achieve arbitrary code execution as root without authentication. Dream recommends disabling Telnet if unnecessary, running telnetd without root where required, blocking port 23, and isolating Telnet access while a fix (expected by April 1, 2026) is developed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.