Cybersecurity

A 32-Year-Old Bug Walks into a Telnet Server

A 32-year-old bug in the GNU inetutils-telnetd package has been found to be exploitable, allowing an attacker to gain root access. The bug, known as CVE-2026-32746, was discovered in the package's code and has been patched. The affected package is used by many Linux distributions, including Debian and Ubuntu. The bug can be exploited by sending a carefully crafted packet to the telnet server, allowing an attacker to execute arbitrary code as root. The vulnerability has been confirmed to affect versions of the package up to 2.3.0.

Read the full article at labs.watchtowr.com →