InfoSec News Nuggets 03/20/2026
Critical Unpatched Telnetd Flaw (CVE-2026-32746) Enables Unauthenticated Root RCE via Port 23 Israeli cybersecurity firm Dream has disclosed CVE-2026-32746 — a CVSS 9.8 out-of-bounds write vulnerability in the LINEMODE Set Local Characters (SLC) suboption handler of the GNU InetUtils telnet daemon that allows an unauthenticated remote attacker to overflow a buffer and execute arbitrary code as root before the login prompt ever appears, simply by sending a specially crafted message during the initial TCP handshake…