CVE-2026-24061. One Command, Root Access: The 11-Year Telnet Bug
Itβs 2026 and attackers are still getting root shells via Telnet with a single command that requires no password whatsoever. π
SSH has existed for 31 years. Yet 221,000 telnet servers are still running online, and a bug hidden in the code since 2015 just handed attackers the keys to the kingdom. CVE-2026-24061. CVSS 9.8. Critical.
The vulnerability sat in GNU InetUtils telnetd for almost 11 years before anyone noticed. Security researcher Kyu Neushwaistein found it on January 20, 2026, and by January 21, attackers were already exploiting it in the wild.