Telcos May Have Received Early Warning of Critical Telnet Vulnerability

Telcos May Have Received Early Warning of Critical Telnet Vulnerability

First seen 12 Feb 2026, 08:51 UTC TheregisterScworld 91% similarity 22.5

Article Content

Browse articles
ThreatCluster

A critical vulnerability in GNU InetUtils telnetd, identified as CVE-2026-24061, was likely known to telecommunications companies prior to its public disclosure. Global Telnet traffic dropped significantly on January 14, 2026, six days before the official security advisories were released on January 20, indicating potential advance warning of the flaw, which has a CVSS score of 9.8 and allows for trivial root access exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-01-14
Global Telnet traffic dropped 65%
2026-01-20
Public disclosure of CVE-2026-24061
2026-01-21
CVE-2026-24061 published
2026-01-21
First public PoC released
2026-01-26
CVE-2026-24061 added to CISA KEV

Community

Browse all →

Tracked Entities in This Story