A critical vulnerability tracked as CVE-2026-32746 was disclosed in GNU InetUtils telnetd affecting version 2.7 and earlier, enabling pre-authentication remote code execution through a buffer overflow in the LINEMODE SLC handler. The flaw stems from a missing bounds check in the add_slc function, which can trigger an out-of-bounds memory write during the Telnet handshake before the login prompt is shown. Security reporting said a remote unauthenticated attacker could exploit the bug to execute code as root, resulting in full system compromise.
The issue was rated CVSS 9.8 and public proof-of-concept exploit code was reported as available, increasing the likelihood of exploitation against exposed Telnet services. Advisories urged organizations to treat internet-accessible telnetd instances as high risk and apply mitigations until patches are available, including restricting access to trusted IP addresses, blocking TCP port 23, or disabling Telnet entirely where it is not operationally required.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that CVE-2026-32746 affects GNU InetUtils telnetd 2.7 and earlier, can be exploited during the telnet handshake before login, and may allow remote code execution as root. The report also stated that proof-of-concept exploit code was publicly available and recommended mitigations until patches are released.
Dream Security published an advisory for CVE-2026-32746, a pre-authentication remote code execution flaw in GNU InetUtils telnetd caused by a buffer overflow in the LINEMODE SLC handler.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcedreamgroup.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.