CVE-2026-32746Disclosure(gnu / inetutils)

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 78 mentions and remains active

Immediate actions

  • Patch gnu inetutils systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • inetutils

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 193 mentions across 32 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 30 signals
  • Patch or workaround mentioned in 32 signals
  • Technical details provided in 151 signals
  • Disclosure: 129 classified signals
  • General: 31 classified signals
  • Peaked 30d ago at 78 mentions (2026-03-18); latest day: 1
  • 193 total mentions across 32 days

Affected systems

Vendors
Products
inetutils

Deep dive

Activity timeline193 mentions / 32d
020395978Mentions · 2026-03-13: 6Mentions · 2026-03-18: 78Mentions · 2026-03-19: 30Mentions · 2026-03-20: 18Mentions · 2026-03-21: 7Mentions · 2026-03-22: 2Mentions · 2026-03-23: 4Mentions · 2026-03-24: 1Mentions · 2026-03-25: 3Mentions · 2026-03-26: 7Mentions · 2026-03-27: 3Mentions · 2026-03-29: 1Mentions · 2026-03-30: 3Mentions · 2026-04-01: 3Mentions · 2026-04-02: 1Mentions · 2026-04-06: 3Mentions · 2026-04-07: 1Mentions · 2026-04-09: 1Mentions · 2026-04-15: 1Mentions · 2026-04-16: 1Mentions · 2026-04-19: 1Mentions · 2026-04-20: 2Mentions · 2026-04-26: 1Mentions · 2026-05-01: 1Mentions · 2026-05-06: 2Mentions · 2026-05-08: 1Mentions · 2026-05-12: 3Mentions · 2026-06-12: 1Mentions · 2026-06-13: 1Mentions · 2026-09-17: 3Mentions · 2026-09-19: 2Mentions · 2026-09-21: 1PoC Mentioned / Linked · 2026-03-18: 14PoC Mentioned / Linked · 2026-03-19: 4PoC Mentioned / Linked · 2026-03-20: 3PoC Mentioned / Linked · 2026-03-23: 2PoC Mentioned / Linked · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-26: 1PoC Mentioned / Linked · 2026-03-27: 1PoC Mentioned / Linked · 2026-03-30: 1PoC Mentioned / Linked · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-06: 1PoC Mentioned / Linked · 2026-04-09: 1Exploit Tool / Code · 2026-03-18: 2Exploit Tool / Code · 2026-03-19: 2Exploit Tool / Code · 2026-03-20: 1Exploit Tool / Code · 2026-03-26: 1Exploit Tool / Code · 2026-03-27: 1Exploit Tool / Code · 2026-04-01: 1Active Exploitation · 2026-03-19: 1Patch / Workaround · 2026-03-18: 18Patch / Workaround · 2026-03-19: 3Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-25: 2Patch / Workaround · 2026-03-26: 3Patch / Workaround · 2026-03-27: 2Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-04-02: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-03-13: 6Technical Details · 2026-03-18: 70Technical Details · 2026-03-19: 19Technical Details · 2026-03-20: 14Technical Details · 2026-03-21: 5Technical Details · 2026-03-23: 4Technical Details · 2026-03-24: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 5Technical Details · 2026-03-27: 3Technical Details · 2026-03-30: 1Technical Details · 2026-04-01: 2Technical Details · 2026-04-06: 3Technical Details · 2026-04-07: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-20: 2Technical Details · 2026-04-26: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-08: 1Technical Details · 2026-05-12: 2Technical Details · 2026-09-17: 2Technical Details · 2026-09-19: 2Technical Details · 2026-09-21: 103-1303-2003-2303-2603-3004-0604-1504-2005-0606-1209-1909-21
Signal classification8 categories
Disclosure
12966.8%
General
3116.1%
Patch
147.3%
PoC
136.7%
Exploit
31.6%
Active Exploitation
10.5%
Referenced assets97 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-136
Disclosure6
2026-03-1878
Disclosure61Exploit1General4Patch7PoC5
2026-03-1930
Active Exploitation1Disclosure18Disclosures1Exploit2General6PoC2
2026-03-2018
Disclosure10Discovery1General5Patch1PoC1
2026-03-217
Disclosure5General2
2026-03-222
General2
2026-03-234
Disclosure4
2026-03-241
General1
2026-03-253
General1Patch1PoC1
2026-03-267
Disclosure4General1Patch1PoC1
2026-03-273
Disclosure1Patch1PoC1
2026-03-291
Disclosure1
2026-03-303
Disclosure1Patch1PoC1
2026-04-013
Disclosure1General1PoC1
2026-04-021
Patch1
2026-04-063
Disclosure3
2026-04-071
Disclosure1
2026-04-091
General1
2026-04-151
Patch1
2026-04-161
General1
2026-04-191
Disclosure1
2026-04-202
Disclosure2
2026-04-261
Disclosure1
2026-05-011
General1
2026-05-062
General2
2026-05-081
Disclosure1
2026-05-123
Disclosure2General1
2026-06-121
General1
2026-06-131
General1
2026-09-173
Disclosure3
2026-09-192
Disclosure2
2026-09-211
Disclosure1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    ⚠️ WARNING - An unpatched critical telnetd bug (CVE-2026-32746) lets attackers gain full system access with no credentials. One connection to port 23 is enough to trigger memory corruption and execute code as root. No patch yet. Prior telnet flaw is already exploited in the wild. 🔗Read → https://thehackernews.com/2026/03/critical-telnetd-flaw-cve-2026-32746.html

    Post summary

    CVE‑2026‑32746 is an unpatched, critical telnetd bug that allows attackers to gain root access with a single connection to port 23. No patch is currently available, and while a related prior flaw has been exploited, this specific vulnerability has no confirmed active exploitation reports.

    60336411.4K637212.7K
    1.1M followersView on X
  • LA₿ 312 | 🛡️InfoSec & Self-Custody 🔑@Lab312_
    Exploit

    ⚠️Root en une connexion. Sans mot de passe. Sans rien. CVE-2026-32746 — CVSS 9.8 Telnet. En 2026. Toujours là. Toujours troué. Buffer overflow dans le daemon telnetd GNU InetUtils. Toutes les versions jusqu'à 2.7. Le bug se déclenche PENDANT le handshake. Avant le login. Avant tout. ☠️ Tu te connectes au port 23 → tu envoies un paquet SLC crafté → t'es root. C'est pas un film. C'est la réalité en mars 2026. Et le meilleur ? Pas de patch. Prévu pour le 1er avril. LOL. Check ta surface d'attaque: nmap -p 23 "ton_ip" Si c'est ouvert → coupe. Immédiatement. Telnet c'est pas vintage, c'est irresponsable. #CVE202632746 #Hacking #RCE #ZeroDay #LAB312

    Post summary

    The post warns that CVE‑2026‑32746 allows root via a crafted Telnet packet, provides technical details and patch timing, but lacks evidence of active exploitation.

    1792248644147.8K
    2.2K followersView on X
  • watchTowr@watchtowrcyber
    Disclosures

    What's new is old, and what's old is new - as is relentlessly proven. Join us in our analysis of CVE-2026-32746, the recent pre-auth RCE in inteutils' Telnetd Speak soon. https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746

    Post summary

    The text offers a brief analysis of CVE‑2026‑32746, describing a pre‑authentication remote code execution flaw in GNU inetutils’ Telnetd, but does not provide any PoC, exploit code, or patch details.

    13821125011.8K
    11.1K followersView on X
  • Cyber Security News@The_Cyber_News
    Disclosure

    🚨 Telnetd Vulnerability Enables Remote Attacker to Execute Arbitrary Code via Port 23 Source: https://cybersecuritynews.com/telnetd-vulnerability-enables-remote-attack/ A critical buffer overflow vulnerability in the GNU Inetutils telnetd daemon. Tracked as CVE-2026-32746, this flaw allows an unauthenticated remote attacker to execute arbitrary code and gain root access to affected systems. The vulnerability requires zero user interaction and possesses a highly trivial exploitation path, prompting an urgent warning for defenders managing legacy infrastructure. An attacker can trigger the classic buffer overflow by sending a specially crafted message during the initial connection handshake. #cybersecuritynews #Linux

    Post summary

    A new critical buffer overflow in GNU Inetutils telnetd (CVE‑2026‑32746) permits unauthenticated remote code execution and root takeover via a specially crafted message during connection handshake.

    4435123267.7K
    51.4K followersView on X
  • Sekurak@Sekurak
    Disclosure

    Krytyczna podatność w serwerze telnet - CVE-2026-32746 ❌ Umożliwia przejęcie serwera (wykonanie wrogiego kodu), z poziomu internetu, bez jakiegokolwiek uwierzytelnienia. 9.8 / 10 w skali CVSS ❌ Trochę przypał bo ktoś ujawnił szczegóły umożliwiające stworzenie exploitu, a łatka pojawi się dopiero... 1 kwietnia ❌ Powiecie - oj tak, przecież nikt nie używa od wielu lat usługi telnet. Na serwerach to prawda, jednak na wielu urządzeniach / IoT / czasem związanych z sieciami przemysłowymi - zdecydowanie tak. Co więcej pewnie ciężko będzie je załatać.

    Post summary

    A critical remote code execution vulnerability (CVE-2026-32746) in telnet servers is announced with a 9.8 CVSS score, and a patch is expected on April 1 despite earlier disclosure of exploit concepts.

    8601253214.7K
    42.7K followersView on X
  • blackorbird@blackorbird
    Disclosure

    A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746 Pre-Auth RCE) https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/ https://t.co/eyFfdTicM7

    Post summary

    The tweet announces CVE-2026-32746, a pre-authentication RCE vulnerability in GNU inetutils Telnetd described as a 32-year-old bug, providing technical vulnerability details (product name, CVE ID, RCE type) and linking to a detailed analysis blog, but without explicitly mentioning PoC code, exploit tools, active exploitation, or remediation steps in the visible text.

    115092376.1K
    44.0K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    CVE-2026-32746: A critical 9.8 CVSS flaw in GNU Telnet allows unauthenticated root access via port 23. Learn why this "Ghost" exploit is an existential threat. #CVE #Telnet #CyberSecurity2026 #RCE #Linux #InfoSec #RootAccess #GNU #CyberAttack #Networking https://meterpreter.org/cve-2026-32746-gnu-inetutils-telnetd-remote-code-execution-fix/ https://t.co/uQgICIftOH

    Post summary

    The tweet announces CVE-2026-32746, a critical RCE flaw in GNU Telnet that allows unauthenticated root access, highlighting its high severity and potential impact.

    312040142.0K
    10.7K followersView on X
  • Censys@censysio
    Disclosure

    🚨Critical vulnerability: CVE-2026-32746 is a pre-authentication remote code execution (RCE) in the telnet daemon. 🛠️ Affects GNU Inetutils telnetd through version 2.7 🔎 Censys sees ~3,362 exposed hosts 🔴 Exploitation could grant an attacker control of the host 🔗Full advisory: https://hubs.ly/Q047s2Kr0 #CVE202632746 #infosec

    Post summary

    A pre‑authentication RCE vulnerability (CVE‑2026‑32746) in the GNU Inetutils telnet daemon has been disclosed, with over 3.3k exposed hosts identified; no active exploitation, PoC, or patch details are reported yet.

    011134183.2K
    12.0K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️ Telnetd Flaw (CVE-2026-32746) PoC https://t.co/XZMc7Oqchf

    Post summary

    The message announces a Proof of Concept for CVE-2026-32746, linking to external content, with no exploit details, active exploitation, or remediation information.

    26038158.2K
    218.4K followersView on X
  • NullSecurityX@NullSecurityX
    Disclosure

    Tracked as CVE-2026-32746, this flaw allows unauthenticated remote code execution with root privileges, affecting all versions through http://youtube.com/@NullSecurityX #BugBounty #CyberSecurity https://t.co/ScYhPQNuJL

    Post summary

    The tweet announces CVE-2026-32746 as a critical unauthenticated RCE that grants root privileges, but provides no evidence of exploitation, patches, or mitigation steps.

    02125183.0K
    11.8K followersView on X
  • Nicolas Krassas@Dinosn
    Discovery

    A 32-Year-Old Bug Walks Into A Telnet Server (GNU inetutils Telnetd CVE-2026-32746) - watchTowr Labs https://labs.watchtowr.com/a-32-year-old-bug-walks-into-a-telnet-server-gnu-inetutils-telnetd-cve-2026-32746/

    Post summary

    The text announces a blog post about CVE-2026-32746, describing a 32‑year‑old bug in GNU inetutils Telnetd, but provides no additional details on PoC, exploit, patching, or active exploitation.

    2312882.7K
    153.4K followersView on X
  • pulpo404@pulpo404
    Disclosure

    ⚠️ WARNUNG - Ein ungepatchter kritischer Fehler in telnetd (CVE-2026-32746) ermöglicht es Angreifern, ohne Anmeldeinformationen vollen Systemzugriff zu erlangen. Eine einzige Verbindung zu Port 23 genügt, um eine Speicherbeschädigung auszulösen und Code als Root auszuführen. Noch kein Patch verfügbar. Die vorherige Telnet-Schwachstelle wird bereits aktiv ausgenutzt.

    Post summary

    CVE-2026-32746 is a critical, unpatched telnetd flaw that allows attackers to gain full root access via a single connection to port 23, causing memory corruption and code execution; no patch is currently available.

    13201723.4K
    12.1K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Synology patches a critical 9.8 CVSS Telnet flaw (CVE-2026-32746). Unauthenticated attackers can hijack your NAS. Update DSM or disable Telnet now! #Synology #CyberSecurity #NAS #InfoSec #RCE #PatchAlert #Vulnerability #DataStorage #TechNews #Telnet #DSM https://securityonline.info/synology-dsm-critical-telnet-rce-vulnerability-cve-2026-32746/ https://t.co/RllDy0uFR7

    Post summary

    Synology issues a patch for the critical CVE-2026-32746 Telnet RCE flaw, urging users to update DSM or disable Telnet to mitigate the high‑severity vulnerability.

    0901561.1K
    10.9K followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @TheHackersNews @TheHackersNews Telnet zero-day hitting root access... this is why we can't have nice legacy things. CVE-2026-32746 is brutal - one connection, memory corruption, you're pwned. Scanning for :23 just got real scary Full details: https://vulntracker.io/cves/CVE-2026-32746

    Post summary

    The post announces a Telnet zero‑day (CVE‑2026‑32746) that allows root access through memory corruption, linking to further details but not providing an exploit or patch.

    0501564.0K
    433 followersView on X
  • /r/netsec@_r_netsec
    PoC

    CVE-2026-32746 GNU telnetd Buffer Overflow PoC - Critical (9.8) https://pwn.guide/free/other/cve-2026-32746

    Post summary

    The message announces the availability of a proof‑of‑concept for the critical GNU telnetd buffer overflow (CVE‑2026‑32746) and links to the relevant code.

    0701081.1K
    32.9K followersView on X
  • Juliano Rizzo@julianor
    Patch

    While we watch TeamPCP supply chain attacks, a 32-year-old telnetd bug (CVE-2026-32746) resurfaced. Pre-auth memory corruption, likely affecting legacy & embedded systems. Same bug patched in the client in 2005.

    Post summary

    A 32‑year‑old telnetd bug (CVE‑2026‑32746) has resurfaced, but it had already been patched in 2005, with no evidence of active exploitation or PoC provided.

    0401552.1K
    9.3K followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    【GNU telnetd重大RCE(CVE-2026-32746)、未認証root取得可能な攻撃が公開】 古典的サービスであるtelnetdに、未認証でroot権限を取得できる致命的脆弱性が公開された。 問題はLINEMODE処理におけるバッファオーバーフローで、リモートから細工されたパケットを送るだけでコード実行が可能になる。CVSS 9.8と評価されている通り、影響は極めて大きい。 注目すべきは、この種の古いサービスが依然として組み込み機器やレガシー環境で残っている点だ。攻撃者は「古いが残っている」サービスを狙う傾向を強めている。 現時点でパッチは未提供であり、公開から悪用までの時間差が極めて短くなる可能性がある。露出しているtelnetは即座にリスクとなる。 #RCE #Telnet #LegacyRisk #CVE202632746 https://thehackernews.com/2026/03/critical-unpatched-telnetd-flaw.html

    Post summary

    The article announces an unpatched, high‑severity RCE vulnerability in GNU telnetd (CVE‑2026‑32746), detailing its technical nature and CVSS score, but does not supply a PoC, exploit code, or evidence of active exploitation.

    1601152.2K
    3.4K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    Critical Unpatched Telnetd Flaw Allows Unauthenticated RCE https://thehackernews.com/2026/03/critical-telnetd-flaw-cve-2026-32746.html

    Post summary

    A CVE‑2026‑32746 flaw in telnetd that enables unauthenticated remote code execution has been disclosed as unpatched; no PoC, exploit, or patch information is included in the text.

    1411252.2K
    153.3K followersView on X
  • Mr. Link@MrLinkEc
    Patch

    🚨 OEEEEE ALERTA CRÍTICA EN NAS Synology 🚨 CVE-2026-32746 (CVSS 9.8) expone dispositivos DSM a ejecución remota de comandos SIN autenticación. No es teórico: es explotable en red si Telnet está activo. 🔎 Contexto técnico: Falla en telnetd (GNU Inetutils ≤ 2.7) Desbordamiento de búfer (CWE-120) en manejo LINEMODE SLC Permite corrupción de memoria → ejecución arbitraria 💣 Impacto real: Los NAS suelen guardar backups y datos críticos, por lo que un atacante puede: Desplegar ransomware Exfiltrar información sensible Mantener persistencia dentro de la red 🛠️ Mitigación: ✔️ Actualiza DSM (7.3.2 / 7.2.2 / 7.2.1 con parches) ✔️ Desactiva Telnet inmediatamente ✔️ Refuerza accesos remotos Si gestionas infraestructura, esto no es opcional. Es riesgo operativo directo. #Ciberseguridad #Synology #NAS #Ransomware #NoSeDejenHackear 😎

    Post summary

    The post warns of CVE‑2026‑32746, a critical buffer‑overflow CVE in Synology DSM's telnet service that allows unauthenticated remote code execution, and urges users to apply the latest DSM patch or disable telnet.

    070141867
    56.4K followersView on X
  • LA₿ 312 | 🛡️InfoSec & Self-Custody 🔑@Lab312_
    General

    🔗Source : https://thehackernews.com/2026/03/critical-telnetd-flaw-cve-2026-32746.html

    Post summary

    The text points to an article about CVE‐2026‑32746 but provides no substantive details or actionable information.

    0201073.7K
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnuinetutils---

Explore more