PoC Released for GNU InetUtils telnetd RCE as 800K+ Exposed Instances Remain Online
A proof-of-concept exploit for CVE-2026-24061, a critical remote code execution vulnerability in the GNU Inetutils telnetd, has surfaced, with security researchers warning that over 800,000 vulnerable instances remain publicly accessible on the internet.
The Shadowserver Foundation’s Accessible Telnet Report reveals the scale of the problem. Approximately 800,000 telnet instances remain exposed on port 23/TCP across the internet, presenting an attractive target surface for mass-exploitation campaigns. Shadowserver’s dashboard provides real-time statistics on accessible telnet instances by country, sector, and ASN.









