CVE-2026-24061: GNU InetUtils Argument Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2026-01-26. EPSS: 99% chance of exploitation in the next 30 days.
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Affected products
Published 2026-01-21. Last modified 2026-09-30.