CVE-2026-24061Critical· 9.8▾ Hadal⚠ Exploited in the wildPoC availabletelnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 53.9 · likelihood 19.8 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 3 sources. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Feb 16, 2026
Last analysed / modified upstream
99%
Exploit-DB · 72 GitHub repos · Metasploit ×1 (last check)
Added to the CISA catalog on Jan 26, 2026. Federal remediation due Feb 16, 2026. View catalog ↗
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
inetutils >= 1.9.3, <= 2.7debian_linux = 11.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86060Critical· 9.8RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation
CVE-2026-91781Low· 3.3A security vulnerability has been detected in GNU Binutils 2.47
CVE-2026-91780Low· 3.3A weakness has been identified in GNU Binutils 2.47
CVE-2026-91779Low· 3.3A security flaw has been discovered in GNU Binutils 2.47
CVE-2026-91752High· 7.5GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data
CVE-2026-90829Medium· 5.3A weakness has been identified in GNU Binutils 2.47