importantSYS.SOURCE: watchTowr• 2026-09-16T02:01:27Z
CVE-2026-32746: Pre-Authentication RCE in GNU inetutils Telnetd
A 32-year-old pre-authentication remote code execution vulnerability (CVE-2026-32746) was discovered in GNU inetutils Telnetd, affecting widely used operating systems through outdated Telnet protocol implementations. The vulnerability stems from a BSS-based buffer overflow in the LINEMODE SLC negotiation handler, posing significant risks due to Telnet's continued use in production environments.
*** END OF TRANSMISSION ***