CVE-2026-24061
published 2026-01-21CVE-2026-24061: telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2026-02-16
Exploited in the wild
EPSS
98.87%
99.9th percentile
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | inetutils | < inetutils 2:2.4-2+deb12u2 (bookworm) | inetutils 2:2.4-2+deb12u2 (bookworm) |
| gnu | inetutils | >= 0 < 2:2.0-1+deb11u3 | 2:2.0-1+deb11u3 |
| gnu | inetutils | >= 0 < 2:2.4-2+deb12u2 | 2:2.4-2+deb12u2 |
| gnu | inetutils | >= 0 < 2:2.6-3+deb13u1 | 2:2.6-3+deb13u1 |
| gnu | inetutils | >= 0 < 2:2.7-2 | 2:2.7-2 |
| gnu | inetutils | 1.9.3 – 2.7 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor telnetd process spawning /usr/bin/login with a '-f' flag argument, which indicates authentication bypass is being attempted. ↗
- →Alert on post-exploitation activity from telnetd sessions: automated reconnaissance, SSH key persistence attempts, and Python malware deployment following unauthenticated root login. ↗
- →Flag inbound Telnet (TCP/23) sessions where the NEW_ENVIRON sub-option contains a USER variable value beginning with '-f', particularly '-f root'. ↗
- →The dominant exploitation source IP 193.24.123.42 (PROSPERO OOO, AS200593) was observed sending 497 exploitation sessions against CVE-2026-24061 targets; block or alert on connections from this IP to TCP/23. ↗
- ·The vulnerability only affects GNU InetUtils telnetd versions 1.9.3 (2015) through 2.7; version 2.8 is patched. Detection rules should be scoped to hosts running these versions. ↗
- ·Exploitation requires the client to send the USER environment variable via Telnet's NEW_ENVIRON/SB sub-negotiation mechanism; telnetd implementations that do not pass USER to login(1) are not affected. ↗
- ·Post-exploitation payload deployment (Python malware, SSH key persistence) was observed to fail on some systems due to missing binaries or directories, so absence of successful payload execution does not rule out initial compromise. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_debian9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Inetutils vulnerability
vendor_ubuntu·2026-02-18
CVE-2026-24061 Inetutils vulnerability
Title: Inetutils vulnerability
Summary: Inetutils could allow unintended access to network services.
USN-7992-1 fixed vulnerabilities in telnetd in Inetutils. This update
provides the corresponding update for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
and Ubuntu 20.04 LTS.
Original advisory details:
Kyu Neushwaistein discovered that telnetd in Inetutils incorrectly handled
certain environment variables. A remote attacker could use this issue to
bypass authentication and open a session as an administrator.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Inetutils vulnerability
vendor_ubuntu·2026-02-02
CVE-2026-24061 Inetutils vulnerability
Title: Inetutils vulnerability
Summary: Inetutils could allow unintended access to network services.
Kyu Neushwaistein discovered that telnetd in Inetutils incorrectly handled
certain environment variables. A remote attacker could use this issue to
bypass authentication and open a session as an administrator.
Instructions: In general, a standard system update will make all the necessary changes.
CISA
GNU InetUtils Argument Injection Vulnerability
cisa·2026-01-26·CVSS 9.8
CVE-2026-24061 [CRITICAL] CWE-88 GNU InetUtils Argument Injection Vulnerability
Vulnerability: GNU InetUtils Argument Injection Vulnerability
Affected: GNU InetUtils
GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://cgit.git.savannah.gnu.org/cgit/inetutils.git ; https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cc; http
Debian
CVE-2026-24061: inetutils - telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "...
vendor_debian·2026·CVSS 9.8
CVE-2026-24061 [CRITICAL] CVE-2026-24061: inetutils - telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "...
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Scope: local
bookworm: resolved (fixed in 2:2.4-2+deb12u2)
bullseye: resolved (fixed in 2:2.0-1+deb11u3)
forky: resolved (fixed in 2:2.7-2)
sid: resolved (fixed in 2:2.7-2)
trixie: resolved (fixed in 2:2.6-3+deb13u1)
GHSA
GHSA-pf97-p8ff-fj35: telnetd in GNU Inetutils through 2
ghsa_unreviewed·2026-01-21
CVE-2026-24061 [CRITICAL] CWE-88 GHSA-pf97-p8ff-fj35: telnetd in GNU Inetutils through 2
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
OSV
CVE-2026-24061: telnetd in GNU Inetutils through 2
osv·2026-01-21·CVSS 9.8
CVE-2026-24061 [CRITICAL] CVE-2026-24061: telnetd in GNU Inetutils through 2
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
VulnCheck
GNU InetUtils Argument Injection Vulnerability
vulncheck·2026·CVSS 9.8
CVE-2026-24061 [CRITICAL] CWE-88 GNU InetUtils Argument Injection Vulnerability
GNU InetUtils Argument Injection Vulnerability
GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable.
Affected: GNU InetUtils
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://viz.greynoise.io/tags/gnu-inetutils-telnetd-authentication-bypass-cve-2026-24061-attempt; https://www.labs.greynoise.io/grimoire/2026-01-22-f-around-and-find-out-18-hours-of-unsolicited-houseguests/index.html; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2026-01-23&host_type=src&vulnerability=cve-2
Suricata
ET WEB_SERVER GNU InetUtils Authentication Bypass via USER Environment Variable (CVE-2026-24061)
suricata·2026-01-23·CVSS 9.8
CVE-2026-24061 [CRITICAL] ET WEB_SERVER GNU InetUtils Authentication Bypass via USER Environment Variable (CVE-2026-24061)
ET WEB_SERVER GNU InetUtils Authentication Bypass via USER Environment Variable (CVE-2026-24061)
Rule: alert tcp any any -> $HOME_NET [23,2323] (msg:"ET WEB_SERVER GNU InetUtils Authentication Bypass via USER Environment Variable (CVE-2026-24061)"; flow:established,to_server; content:"|ff fa 27 00 00|USER|01|"; fast_pattern; content:"-f"; distance:0; pcre:"/^\s+[\w-]+\xff\xf0/Ri"; reference:url,seclists.org/oss-sec/2026/q1/89; reference:cve,2026-24061; classtype:attempted-admin; sid:2067186; rev:2; metadata:attack_target Client_and_Server, created_at 2026_01_23, cve CVE_2026_24061, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2026_01_30, former_sid 2865814; target:dest_ip;)
Elastic
Telnet Authentication Bypass via User Environment Variable
elastic_rules·CVSS 9.8
CVE-2026-24061 [CRITICAL] Telnet Authentication Bypass via User Environment Variable
Telnet Authentication Bypass via User Environment Variable
Identifies potential exploitation of a Telnet remote authentication bypass vulnerability (CVE-2026-24061) in GNU Inetutils
telnetd. The vulnerability allows unauthenticated access by supplying a crafted `-f ` value via the `USER` environment
variable, resulting in a login process spawned with elevated privileges.
Query:
sequence by host.id with maxspan=1s
[process where host.os.type == "linux" and event.type == "start" and event.action in ("process_started", "executed") and process.name in ("telnetd", "xinetd")] by process.pid
[process where host.os.type == "linux" and event.type == "start" and event.action in ("process_started", "executed") and process.name == "login" and process.args : "-*f*"] by process.parent.pid
Elastic
Potential Telnet Authentication Bypass (CVE-2026-24061)
elastic_rules·CVSS 9.8
CVE-2026-24061 [CRITICAL] Potential Telnet Authentication Bypass (CVE-2026-24061)
Potential Telnet Authentication Bypass (CVE-2026-24061)
Identifies potential exploitation of a Telnet remote authentication bypass vulnerability (CVE-2026-24061) in GNU Inetutils
telnetd. The vulnerability allows unauthenticated access by supplying a crafted `-f ` value via the `USER` environment
variable, resulting in a login process spawned with elevated privileges.
Query:
process where host.os.type == "linux" and event.type == "start" and
event.action in ("exec", "exec_event", "start", "ProcessRollup2", "executed") and
process.name == "login" and process.parent.name in ("telnetd", "xinetd") and process.args : "-*f*"
Exploit-DB
GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation
exploitdb·2026-04-29·CVSS 9.8
CVE-2026-24061 [CRITICAL] GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation
GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation
---
# Exploit Title: GNU InetUtils telnetd - Remote Privilege Escalation
# Date: 2026-01-24
# Exploit Author: Ali Guliyev (infat0x)
# Author GitHub: https://github.com/infat0x
# Vendor Homepage: https://www.gnu.org/software/inetutils/
# Software Link: https://ftp.gnu.org/gnu/inetutils/
# Version: GNU InetUtils 2.0 through 2.6
# Tested on: Linux (various distributions using vulnerable inetutils-telnetd)
# CVE : CVE-2026-24061
import socket
import sys
import threading
import argparse
import re
"""
Description:
The telnetd implementation in GNU InetUtils before 2.7-2 is vulnerable to
authentication bypass via environment variable injection. By passing a
crafted USER environment variable (e.g., "-f root") during the Telnet
NEW-ENVIRON
Metasploit
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
metasploit·CVSS 9.8
CVE-2026-24061 [CRITICAL] GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
GNU Inetutils Telnet Authentication Bypass Exploit CVE-2026-24061
The telnetd service from GNU InetUtils is vulnerable to authentication-bypass, tracked as CVE-2026-24061, in versions up to version 2.7. During Telnet authentication the SB byte can be sent to indicate sub-negotiation which allows for the exchange of sub-option parameters after both parties have agreed to enable a specific functional option. Environment variables can be sent as sub-options and it's the USER environment variable which introduces the authentication bypass in this scenario. When the USER environment variable gets sent to the GNU inetutils telnetd service during authentication, the variable gets appended without proper sanitization to an execv call to the /usr/bin/login binary. The login binary has a -f flag wh
Nuclei
GNU Inetutils telnetd - Authentication Bypass
nuclei·CVSS 9.8
CVE-2026-24061 [CRITICAL] GNU Inetutils telnetd - Authentication Bypass
GNU Inetutils telnetd - Authentication Bypass
GNU Inetutils telnetd through 2.7 contains an authentication bypass caused by setting the USER environment variable to \"-f root\", letting remote attackers bypass authentication, exploit requires remote access to telnetd service.
Template:
id: CVE-2026-24061
info:
name: GNU Inetutils telnetd - Authentication Bypass
author: pussycat0x
severity: critical
description: |
GNU Inetutils telnetd through 2.7 contains an authentication bypass caused by setting the USER environment variable to \"-f root\", letting remote attackers bypass authentication, exploit requires remote access to telnetd service.
remediation: |
Update to a version later than 2.7 or the latest available version.
impact: |
Remote attackers can bypass authentication, gaining una
Securelist
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
blogs_securelist·2026-05-29
CVE-2025-55182 What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
Yaroslav Shmelev
Anton Kivva
Denis Parinov
Vladimir Kuskov
Yanina Balandyuk-Opalinskaya
Table of Contents
Introduction
Software vulnerabilities and compromise of update sources
Configuration vulnerabilities
Insecure handling of credentials
Use of default passwords
Passing passwords via command arguments
Privilege escalation in the container
Attacks on sudo
Insecure file permissions
Lack of integrity checks
Conclusion
Authors
Yaroslav Shmelev
Anton Kivva
Denis Parinov
Vladimir Kuskov
Yanina Balandyuk-Opalinskaya
## Introduction
Containerization using Docker has become firmly established in modern development standards, significantly increasing the speed and convenience of deploying various services. Developers often use ready-made Docker images, making only minimal c
Bleepingcomputer
One threat actor responsible for 83% of recent Ivanti RCE attacks
blogs_bleepingcomputer·2026-02-14·CVSS 9.8
CVE-2026-1286 [CRITICAL] One threat actor responsible for 83% of recent Ivanti RCE attacks
## One threat actor responsible for 83% of recent Ivanti RCE attacks
## Bill Toulas
Update: The article initially listed the wrong CVEs. This has now been corrected to list the CVEs: CVE-2026-1286 and CVE-2026-1340
Threat intelligence observations show that a single threat actor is responsible for most of the active exploitation of two critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1281 and CVE-2026-1340.
The security issues have been flagged as actively exploited in zero-day attacks in Ivanti's security advisory, where the company also announced hotfixes.
Both flaws received a critical severity rating and allow an attacker to inject code without authentication, leading to remote code execution (RCE) on vulnerable systems.
A single IP address h
Greynoiseio
Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point Elsewhere
blogs_greynoiseio·2026-02-10
Active Ivanti Exploitation Traced to Single Bulletproof IP—Published IOC Lists Point Elsewhere
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Bleepingcomputer
Nearly 800,000 Telnet servers exposed to remote attacks
blogs_bleepingcomputer·2026-01-26·CVSS 9.8
CVE-2026-24061 [CRITICAL] Nearly 800,000 Telnet servers exposed to remote attacks
## Nearly 800,000 Telnet servers exposed to remote attacks
## Sergiu Gatlan
Internet security watchdog Shadowserver tracks nearly 800,000 IP addresses with Telnet fingerprints amid ongoing attacks exploiting a critical authentication bypass vulnerability in the GNU InetUtils telnetd server.
The security flaw (CVE-2026-24061) already has a proof-of-concept exploit , impacts GNU InetUtils versions 1.9.3 (released in 2015) through 2.7, and was patched in version 2.8 (released on January 20).
"The telnetd server invokes /usr/bin/login (normally running as root) passing the value of the USER environment variable received from the client as the last parameter," explained open-source contributor Simon Josefsson, who reported it.
"If the client supply a carefully crafted USER environment valu
Bleepingcomputer
Hackers exploit critical telnetd auth bypass flaw to get root
blogs_bleepingcomputer·2026-01-23·CVSS 9.8
CVE-2026-24061 [CRITICAL] Hackers exploit critical telnetd auth bypass flaw to get root
## Hackers exploit critical telnetd auth bypass flaw to get root
## Bill Toulas
A coordinated campaign has been observed targeting a recently disclosed critical-severity vulnerability that has been present in the GNU InetUtils telnetd server for 11 years.
The security issue is tracked as CVE-2026-24061 and was reported on January 20. It is trivial to leverage and multiple exploit examples are publicly available.
## Bug persisted since 2015
Open-source contributor Simon Josefsson explains that the telnetd component of GNU InetUtils contains a remote-authentication bypass vulnerability caused by unsanitized environment variable handling when spawning ‘/usr/bin/login.’
The flaw occurs because telnetd passes the user-controlled USER environment variable directly to login(1) without sanit
Wiz
CVE-2026-32772 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-32772 [HIGH] CVE-2026-32772 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32772 :
GNU InetUtils Telnet vulnerability analysis and mitigation
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.
Source : NVD
## 3.4
Score
Published March 16, 2026
Severity LOW
CNA Score 3.4
Affected Technologies
GNU InetUtils Telnet
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.5
Exploitation Probability (EPSS) N/A
Affected packages and libraries
inetutils
cpe:2.3:a:gnu:inetutils
Sources
NVD
Debian 11 Severity LOW No Fix Added at: Mar 14, 2026
Debian 12, 13, 14 Severity LOW Has Fix Added at: Mar 14, 2026
Echo Severity LOW Has Fix Added at: Mar 14, 2026
Linux
Wiz
CVE-2026-24061 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.8
CVE-2026-24061 [CRITICAL] CVE-2026-24061 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24061 :
NixOS vulnerability analysis and mitigation
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Source : NVD
## 9.8
Score
Published January 21, 2026
Severity CRITICAL
CNA Score 9.8
High-profile Vulnerability Yes
Affected Technologies
NixOS
Homebrew
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 99.4
Exploitation Probability (EPSS) 87
Affected packages and libraries
cpe:2.3:a:gnu:inetutils
net-misc/inetutils
Sources
Debian 11, 12, 13, 14 Severity CRITICAL Has Fix Added at: Jan 22, 2026
Echo Severity CRITICAL Has Fix Added at: Jan 21, 2026
Gentoo Severity HIGH Has Fix Added at:
Wiz
CVE-2026-32746 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-32746 [HIGH] CVE-2026-32746 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-32746 :
GNU InetUtils Telnet vulnerability analysis and mitigation
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.
Source : NVD
## 9.8
Score
Published March 13, 2026
Severity CRITICAL
CNA Score 9.8
High-profile Vulnerability Yes
Affected Technologies
GNU InetUtils Telnet
Linux Debian
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.6
Exploitation Probability (EPSS) N/A
Affected packages and libraries
krb5-appl-clients
krb5-appl-servers
Sources
Debian 11 Severity CRITICAL No Fix Added at: Mar 14, 2026
Debian 12, 13, 14 Severity
Recorded Future
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
blogs_recorded_future·CVSS 4.9
[MEDIUM] January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
# January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
January 2026 saw a modest 5% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 23 vulnerabilities requiring immediate remediation, up from 22 in December 2025. Noteworthy trends last month included Russian state-sponsored exploitation of a Microsoft Office zero-day and critical authentication bypass flaws affecting enterprise infrastructure.
What security teams need to know:
- APT28's Operation Neusploit: Russian state-sponsored actors exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files, delivering MiniDoor, PixyNetLoader, and Covenant Grunt implants
- Microsoft and SmarterTools lead concerns: These vendors accounte
https://codeberg.org/inetutils/inetutils/commit/ccba9f748aa8d50a38d7748e2e60362edd6a32cchttps://codeberg.org/inetutils/inetutils/commit/fd702c02497b2f398e739e3119bed0b23dd7aa7bhttps://lists.gnu.org/archive/html/bug-inetutils/2026-01/msg00004.htmlhttps://www.gnu.org/software/inetutils/https://www.openwall.com/lists/oss-security/2026/01/20/2https://www.openwall.com/lists/oss-security/2026/01/20/8https://www.vicarius.io/vsociety/posts/cve-2026-24061-detection-script-remote-authentication-bypass-in-gnu-inetutils-packagehttps://www.vicarius.io/vsociety/posts/cve-2026-24061-mitigation-script-remote-authentication-bypass-in-gnu-inetutils-packagehttp://www.openwall.com/lists/oss-security/2026/01/22/1https://lists.debian.org/debian-lts-announce/2026/01/msg00025.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-24061https://www.labs.greynoise.io/grimoire/2026-01-22-f-around-and-find-out-18-hours-of-unsolicited-houseguests/index.htmlhttps://www.openwall.com/lists/oss-security/2026/01/20/2#:~:[email protected]%3A~%20USER='
2026-01-21
Published
2026-01-26
Added to CISA KEV
Exploited in the wild