CVE-2026-24061
CRITICAL
CVSS: 9.8
EPSS: 98.0%
VulnCheck KEV
Weaponized
Metasploit
ExploitDB
CWE-88
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Published: 2026-01-21