Skip to content

CVE-2026-24061

CVE

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
January 22, 2026
Last Seen
March 18, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability, CVE-2026-32746, has been discovered in the GNU InetUtils telnetd daemon, affecting all versions up to and including 2.7. This flaw allows unauthenticated remote attackers to execute arbitrary code with root privileges by sending a specially crafted message during the Telnet...

CVE-2026-24061 is a remote authentication bypass vulnerability in GNU InetUtils telnetd, affecting versions 1.9.3 through 2.7. An unauthenticated attacker can exploit this flaw by supplying a specially crafted USER environment variable, allowing root-level access. The vulnerability has a CVSS score...

A critical vulnerability in the GNU InetUtils telnet daemon (telnetd), tracked as CVE-2026-24061, allows attackers to bypass authentication and gain root access. Disclosed on January 20, 2026, the flaw has existed for nearly 11 years and was introduced in a May 2015 update. Users still running telne...

Two vulnerabilities in Ivanti Endpoint Manager Mobile (CVE-2026-21962 and CVE-2026-24061) have been flagged as actively exploited in zero-day attacks. A single IP address is responsible for over 83% of exploitation activity related to these vulnerabilities, as reported by GreyNoise. Ivanti has relea...

Public Exploits

Checking GitHub for proof-of-concept code…