GreyNoise reported a sudden, sustained step-function collapse in global Telnet traffic beginning around 21:00 UTC on 2026-01-14, dropping from roughly 65k–74k hourly sessions to about 11k within two hours (an ~83% decline) and then holding at a lower baseline. GreyNoise assessed the change as a structural shift in Internet “plumbing” (not normal scanner churn or a telemetry issue) and noted the drop preceded public disclosure of CVE-2026-24061 (posted to oss-security on 2026-01-20) and CISA’s subsequent addition of the CVE to the Known Exploited Vulnerabilities (KEV) catalog (by 2026-01-26), suggesting the traffic collapse and exploitation activity may be related.
Despite the global reduction, Asia-Pacific networks showed comparatively weaker suppression of Telnet, leaving continued exposure from insecure, legacy Telnet services on devices such as consumer-grade routers. GreyNoise data cited by Dark Reading indicated inconsistent national-level filtering in the region—Taiwan blocked ~77% of Telnet sessions (the strongest in the region), while India (~70%), Japan (~65%), and China (~59%) reduced traffic less aggressively—contrasting with countries such as Ukraine and Canada that reportedly blocked Telnet traffic entirely. The net effect is that while backbone-level controls appear to have materially reduced global Telnet scanning and session volume, organizations operating in lagging jurisdictions may still face elevated risk from Telnet-exposed assets and exploitation tied to CVE-2026-24061.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
On February 10, 2026, GreyNoise published its analysis concluding the January 14 collapse most likely reflected infrastructure-level port 23 filtering by one or more transit providers rather than a normal decline in scanning. The researchers noted the depressed and volatile post-drop environment persisted through at least February 10 and hypothesized, without proof, that advance notice of the vulnerability may have prompted the filtering.
Following disclosure, GreyNoise reported active exploitation of the telnetd authentication-bypass flaw, with exploitation peaking around early February before tapering. The activity reinforced the urgency of patching to GNU Inetutils 2.7-2 or later or disabling Telnet entirely.
Four days after the public advisory, CISA added CVE-2026-24061 to its Known Exploited Vulnerabilities catalog. The KEV listing established a federal remediation deadline of February 16, 2026 for affected organizations.
On January 20, 2026, a public advisory disclosed CVE-2026-24061, a critical authentication-bypass flaw in GNU Inetutils telnetd. The bug allows USER argument injection that can enable a root login bypass via "-f root," and was described as trivial to exploit.
Beginning after the January 14 traffic collapse, GreyNoise saw 18 high-volume autonomous systems drop to zero observed Telnet sessions and five countries—Zimbabwe, Ukraine, Canada, Poland, and Egypt—vanish entirely from its Telnet dataset. Major cloud providers were largely unaffected or even increased, suggesting the impact was concentrated in specific transit paths or filtering domains.
Around 21:00 UTC on January 14, 2026, GreyNoise observed a sudden step-function drop in global Telnet (TCP/23) activity, with sessions falling sharply within hours and daily volume dropping from about 914,000 to roughly 373,000. The change appeared sustained rather than transient, indicating a major shift in Internet-wide Telnet reachability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcego.theregister.com
Open sourcelabs.greynoise.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.