Changeflow GovPing Data Privacy & Cybersecurity GNU InetUtils Multiple Vulnerabilities (CVSS 9.8)
Urgent Notice Added Final

GNU InetUtils Multiple Vulnerabilities (CVSS 9.8)

Favicon for wid.cert-bund.de CERT-Bund Security Advisories
Published March 15th, 2026
Detected March 16th, 2026
Email

Summary

CERT-Bund has issued a security advisory (WID-SEC-2026-0734) regarding critical vulnerabilities in GNU InetUtils versions up to 2.7. These vulnerabilities, rated CVSS 9.8, allow for remote code execution and information disclosure on Linux and UNIX systems. Users are advised to update their systems.

What changed

CERT-Bund has released a critical security advisory (WID-SEC-2026-0734) detailing multiple vulnerabilities in GNU InetUtils, affecting versions up to 2.7. The vulnerabilities have a critical CVSS Base Score of 9.8 and a Temporal Score of 9.0, indicating a high risk of remote exploitation. Successful exploitation can lead to arbitrary code execution and information disclosure on affected Linux and UNIX systems.

Organizations utilizing GNU InetUtils should immediately assess their systems for vulnerable versions. While no specific mitigation is provided, prompt updating to a patched version or implementing compensating controls is strongly recommended to prevent exploitation. The advisory highlights the urgent need for system administrators to address these critical security flaws to protect against potential attacks.

What to do next

  1. Assess systems for GNU InetUtils versions <= 2.7
  2. Update GNU InetUtils to a patched version
  3. Implement compensating controls if immediate update is not possible

Source document (simplified)

[WID-SEC-2026-0734] GNU InetUtils: Mehrere Schwachstellen CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 9.0 (kritisch) Remoteangriff ja Datum 15.03.2026 Stand 16.03.2026 Mitigation nein

Betroffene Systeme

Betriebssystem

  • Linux
  • UNIX

Produktbeschreibung

Inetutils ist eine Sammlung von grundlegenden Netzwerkprogrammen für Unix-ähnliche Betriebssysteme.

Produkte

15.03.2026
- Open Source InetUtils <=2.7

Angriff

Angriff

Ein Angreifer kann mehrere Schwachstellen in GNU InetUtils ausnutzen, um beliebigen Programmcode auszuführen, und um Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-Bund
Published
March 15th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive

Who this affects

Applies to
Technology companies
Geographic scope
Germany

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Topics
Software Vulnerabilities Network Security

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-Bund Security Advisories publishes new changes.

Free. Unsubscribe anytime.