Why CVE-2026-32746 Grants Root Access to Telnetd [Prime Cyber Insights]

Cybersecurity researchers at Dream have identified a critical unpatched vulnerability in the GNU InetUtils telnet daemon, tracked as CVE-2026-32746. With a CVSS score of 9.8, this flaw allows unauthenticated remote attackers to execute arbitrary code with root privileges by exploiting an out-of-bounds write in the LINEMODE Set Local Characters (SLC) suboption handler. The vulnerability is particularly dangerous because it can be triggered during the initial connection handshake on port 23 before any login prompt appears. Discovered by researcher Adiel Sol, the flaw affects all versions through 2.7. While a fix is expected by April 1, 2026, practitioners are advised to disable the service or block port 23 immediately. This disclosure follows a similar critical flaw from earlier this year, CVE-2026-24061, which CISA reports is already seeing active exploitation.

Practitioners are facing a significant new risk as researchers at Dream disclose CVE-2026-32746, a critical 9.8-rated vulnerability in the GNU InetUtils telnet daemon. The flaw permits unauthenticated remote code execution (RCE) with root privileges, requiring only a single network connection to port 23. Because the overflow occurs during protocol negotiation before authentication, attackers can gain full system control without credentials. With a patch not expected until April 1st, organizations must prioritize immediate mitigations such as service isolation or port blocking to prevent total system compromise.

Topics Covered

  • ⚠️ Understanding the CVE-2026-32746 Root RCE flaw
  • 🌐 Why port 23 remains a critical exposure point
  • 🛡️ Mitigating unpatched vulnerabilities in GNU InetUtils
  • 📊 Analyzing the recurring security issues in Telnet services

Disclaimer: This briefing is for informational purposes and based on reports from The Hacker News and Dream security research.

Neural Newscast is AI-assisted, human reviewed. View our AI Transparency Policy at NeuralNewscast.com.

Why CVE-2026-32746 Grants Root Access to Telnetd [Prime Cyber Insights]
Broadcast by