CVE-2026-24061: listed in the CISA KEV catalog
CVE-2026-24061 · CVSS 9.8 CRITICAL · EPSS 99% · KEV 2026-01-26
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Is CVE-2026-24061 exploited?
- Listed in the CISA KEV catalog on 2026-01-26.
- Federal remediation due 2026-02-16.
- Past that date by 227 days.
- EPSS puts exploitation in the next 30 days at 99%.
- Public exploit code: packaged in a public tool.
Which products and versions are affected?
- GNU · Inetutils · 1.9.3 - 2.7
- debian · debian linux · 11.0
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2026-24061
PlainSec has not published a story about this CVE.
Primary sources
What this record does not say
KEV and EPSS are re-checked daily. Record last updated 2026-09-24.