telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
https://www.openwall.com/lists/oss-security/2026/01/20/2#:~:[email protected]%3A~%20USER='
https://lists.debian.org/debian-lts-announce/2026/01/msg00025.html
https://www.cisa.gov/sites/default/files/2026-08/cisa-vulnerability-review-fy-2024-2025.pdf
https://thehackernews.com/2026/03/critical-telnetd-flaw-cve-2026-32746.html
https://thehackernews.com/2026/02/83-of-ivanti-epmm-exploits-linked-to.html
https://www.labs.greynoise.io/grimoire/2026-02-10-telnet-falls-silent/
https://www.greynoise.io/blog/active-ivanti-exploitation
https://www.securityweek.com/organizations-warned-of-exploited-linux-vulnerabilities/
https://www.databreachtoday.com/telnet-flaw-800000-servers-at-risk-amid-active-attacks-a-30604
https://www.darkreading.com/ics-ot-security/critical-telnet-server-flaw-forgotten-attack-surface
https://securelist.com/container-security-typical-issues/119974/
https://www.theregister.com/2026/02/11/were_telcos_tipped_off_to/
https://www.theregister.com/2026/01/22/root_telnet_bug/
https://thehackernews.com/2026/01/critical-gnu-inetutils-telnetd-flaw.html
https://github.com/cipher131/cve-exploit-mapper
https://github.com/0p5cur/CVE-2026-62737-POC
https://github.com/s-vx/CVE-2026-24061
https://github.com/stoerti2/Abyssal
https://github.com/Hector-Abarca/realrisk-checks
https://github.com/Cosm3No1de/htb-orion-writeup
https://github.com/tc4dy/CVE-2026-41091-PoC-Exploit
https://github.com/akpmarcelin/CVE-2026-24061-lab
https://github.com/tc4dy/CVE-2026-24061-PoC-Exploit
https://github.com/ahmadsadeeq/TelnetdBypass-
https://github.com/1392081456/sigma-detection-rules
https://github.com/tc4dy/CVE-2026-0073-PoC-Exploit
https://github.com/tc4dy/CVE-2026-41940-PoC-Exploit
https://github.com/1392081456/ctf-notes
https://github.com/RStephanH/vuln-deb
https://github.com/mrhenrike/EmbedXPL-Forge
https://github.com/ekomsSavior/telnet_scan
https://github.com/przemytn/CVE-2026-24061
https://github.com/HD0x01/CVE-2026-24061-NSE
https://github.com/EvanThomasLuke/HACK-AGI-CONTAINERS
https://github.com/0xAshwesker/CVE-2026-24061
https://github.com/anacarsi/CVEs-exploit-2026
https://github.com/Remnant-DB/CVE-2026-24061
https://github.com/setuju/telnetd
https://github.com/athack-ctf/chall2026-telneted
https://github.com/tiborscholtz/CVE-2026-24061
https://github.com/nrnw/CVE-2026-24061-GNU-inetutils-Telnet-Detector
https://github.com/killsystema/scan-cve-2026-24061
https://github.com/canpilayda/inetutils-telnetd-cve-2026-24061
https://github.com/lavabyte/telnet-CVE-2026-24061
https://github.com/obrunolima1910/obrunolima1910.github.io
https://github.com/obrunolima1910/CVE-2026-24061
https://github.com/Moxxic1/moxxic1.github.io
https://github.com/Moxxic1/Tell-Me-Root
https://github.com/Good123321-bot/good123321-bot.github.io
https://github.com/olatunbosunoyeleke94/telnet-sec
https://github.com/SeptembersEND/CVE--2026-24061
https://github.com/franckferman/CVE_2026_24061_PoC
https://github.com/franckferman/CVE_2026_24061
https://github.com/XiaomingX/data-cve-poc-py-v1
https://github.com/ridpath/Terrminus-CVE-2026-2406
https://github.com/dotelpenguin/telnetd_CVE-2026-24061_tester
https://github.com/Parad0x7e/CVE-2026-24061
https://github.com/0x7556/CVE-2026-24061
https://github.com/hilwa24/CVE-2026-24061
https://github.com/MY0723/GNU-Inetutils-telnet-CVE-2026-24061-
https://github.com/Gabs-hub/CVE-2026-24061_Lab
https://github.com/novitahk/Exploit-CVE-2026-24061
https://github.com/cumakurt/tscan
https://github.com/FurkanKAYAPINAR/CVE-2026-24061-telnet2root
https://github.com/LucasPDiniz/CVE-2026-24061
https://github.com/Lingzesec/cve-2026-24061-GUI
https://github.com/Lingzesec/CVE-2026-24061-GUI
https://github.com/XsanFlip/CVE-2026-24061-Scanner
https://github.com/punitdarji/telnetd-cve-2026-24061
https://github.com/ms0x08-dev/CVE-2026-24061-POC
https://github.com/typeconfused/CVE-2026-24061
https://github.com/DeadlyHollows/CVE-2026-24061-setup
https://github.com/BrainBob/Telnet-TestVuln-CVE-2026-24061
https://github.com/BrainBob/CVE-2026-24061
https://github.com/Mr-Zapi/CVE-2026-24061
https://github.com/z3n70/CVE-2026-24061
https://github.com/splinterlabs/osint-agent-public
https://github.com/r00tuser111/CVE-2026-24061
https://github.com/m3ngx1ng/cve_2026_24061_cli
https://github.com/Ashwesker/Ashwesker-CVE-2026-24061
https://github.com/monstertsl/CVE-2026-24061
https://github.com/h3athen/CVE-2026-24061
https://github.com/SafeBreach-Labs/CVE-2026-24061
https://github.com/TryA9ain/CVE-2026-24061
https://github.com/duy-31/CVE-2026-24061---telnetd
https://github.com/leonjza/inetutils-telnetd-auth-bypass
https://github.com/Hatchepsoute/sigma-rules
https://www.openwall.com/lists/oss-security/2026/01/20/8
https://www.openwall.com/lists/oss-security/2026/01/20/2
https://www.gnu.org/software/inetutils/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24061
https://lists.gnu.org/archive/html/bug-inetutils/2026-01/msg00004.html
https://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739e3119bed0b23dd7aa7b
https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc
Published: 2026-01-21
Updated: 2026-02-11
Known Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.98064
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored