CVE-2026-24061
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
- Published Jan 21, 2026
- CVSS 9.8 critical
- 99.0% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A Metasploit module exploits it
- A fix is available
Affected software
In the news
- Quantifying 2026 Routinely Targeted Vulnerabilities (So Far) VulnCheck Blog ·