Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability

Remote telnetd bypass reaches root on GNU InetUtils

Updated 14.02.2026 18:02
Case score 59
Case score 59 Members 1 Latest activity 14.02.2026 18:02 Active exploitation Patch available CVSS: 9.8 Critical
Active exploitation Patch available CVSS: 9.8 Critical
Members 1 First seen 22.01.2026 18:30 Last seen 22.01.2026 18:30 Updated 14.02.2026 18:02

Overview

A critical remote authentication bypass in **GNU InetUtils telnetd** lets remote clients skip login and reach **root** on affected releases. **CVE-2026-24061** affects **GNU InetUtils 1.9.3 through 2.7**, and probing has already been observed from multiple countries after disclosure. Patch, restrict telnet to trusted clients, or disable telnetd; a custom `login(1)` that rejects `-f` is another mitigation. Available evidence confirms active probing, but successful compromise and victim counts are not established.