Securityaffairs.Co Critical RCE Vulnerability in GNU InetUtils telnetd Exposes Systems to Attacks
Article Content
- •CVE-2026-32746 allows unauthenticated RCE via GNU InetUtils telnetd on port 23.
- •The vulnerability has a CVSS score of 9.8 and affects all versions up to 2.7.
- •Immediate action is required to mitigate risks, with a patch expected on April 1, 2026.
A critical vulnerability, CVE-2026-32746, has been discovered in the GNU InetUtils telnetd daemon, affecting all versions up to and including 2.7. This flaw allows unauthenticated remote attackers to execute arbitrary code with root privileges by sending a specially crafted message during the Telnet handshake on port 23. The vulnerability is classified as a buffer overflow and has a CVSS score of 9.8, indicating its critical nature. It poses a significant risk, especially to Industrial Control Systems (ICS) and operational technology (OT) environments where Telnet is still widely used. As of now, there are no confirmed instances of active exploitation, but the potential for imminent attacks is high due to the availability of technical details in public forums. Organizations are urged to restrict access to telnetd and consider migrating to more secure protocols like SSH. A patch is expected to be released on April 1, 2026, but until then, immediate mitigation measures are necessary.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (9)
Following this threat?
Track CVE-2026-24061 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…