Researchers disclosed CVE-2026-32746, a critical telnetd vulnerability in GNU Inetutils that allows an unauthenticated remote attacker to achieve root remote code execution by exploiting a buffer overflow in the LINEMODE SLC (Set Local Characters) option handler. The flaw affects GNU Inetutils telnetd through version 2.7, carries a CVSS 9.8, and can be triggered during the initial Telnet handshake on port 23 before any login prompt appears, requiring no credentials, no user interaction, and no special network position.
The issue was discovered and reported by Dream on March 11, 2026, and GNU maintainers reportedly confirmed the finding, with a fix expected by April 1, 2026. Both reports warn that successful exploitation can lead to full system compromise because telnetd often runs with elevated privileges, enabling follow-on activity such as persistent backdoors, data theft, and lateral movement. The risk is especially acute in legacy environments where Telnet remains in use, including ICS/OT, PLC, SCADA, and some government systems, even though public reporting has not yet indicated active exploitation in the wild.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
GNU announced the stable release of inetutils 2.8 on 2026-04-29, delivering the upstream fix for the telnetd RCE flaw CVE-2026-32746. The release also addressed telnetd authentication bypass CVE-2026-24061, mitigated privilege-escalation issue CVE-2026-28372, and included additional telnet/telnetd hardening changes.
Debian published security advisory DSA 6193-1 announcing a security update for inetutils to address the telnetd vulnerability tracked as CVE-2026-32746. The advisory marks a downstream distribution patch release following earlier disclosure and analysis of the flaw.
Public disclosures stated that the official GNU InetUtils release containing the fix for CVE-2026-32746 was expected on 2026-04-01. This was presented as the anticipated patch date rather than a confirmed release at the time of reporting.
Synology warned that CVE-2026-32746 affects DiskStation Manager and related products via the GNU InetUtils telnetd daemon, exposing systems to unauthenticated command execution. The company released fixes for DSM 7.3, 7.2.2, and 7.2.1, said a DSMUC 3.1 fix was still in development, and advised customers to disable Telnet as a mitigation.
watchTowr Labs released a deeper technical analysis showing the bug dates back to 1994, affects GNU inetutils-telnetd and downstream implementations, and can yield impactful exploitation primitives even if universal RCE was not achieved. The researchers also published a detection artifact generator and noted that Debian sid/forky had fixes while many other distributions still had not shipped patches.
Multiple outlets reported the public disclosure of CVE-2026-32746, an unauthenticated root-level RCE in GNU InetUtils telnetd caused by an out-of-bounds write or buffer overflow in LINEMODE SLC negotiation during the Telnet handshake. The flaw affects all telnetd versions through 2.7 and was described as trivial to trigger with crafted traffic to port 23 before authentication.
Following the report, GNU InetUtils maintainers confirmed the telnetd vulnerability and approved a fix for release. Public reporting said an official patched release was expected on 2026-04-01.
Dream Security discovered and reported CVE-2026-32746, a critical pre-authentication remote code execution flaw in GNU InetUtils telnetd, to the project maintainers. The report was submitted on 2026-03-11, according to later public disclosures.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
my.f5.com
Open sourcecyber.gc.ca
Open sourcelists.debian.org
Open sourcecybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcegbhackers.com
Open sourcecvereports.com
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.