<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — GNU</title><description>Actively exploited vulnerabilities affecting GNU products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/gnu.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-24061 — GNU InetUtils Argument Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-24061</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-24061</guid><description>GNU InetUtils&apos; telnetd daemon contains an argument injection flaw that lets a remote attacker bypass authentication entirely by supplying a specially crafted USER environment variable value of &apos;-f root&apos;. Because telnet is often used in legacy or embedded environments, a successful exploit grants an unauthenticated attacker access — potentially as root — without valid credentials. This is a critical risk for any system running the affected telnetd service, as it requires no prior foothold.</description><pubDate>Mon, 26 Jan 2026 00:00:00 GMT</pubDate><category>GNU</category><category>InetUtils</category></item><item><title>CVE-2014-6278 — GNU Bash OS Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2014-6278</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2014-6278</guid><description>This is a Shellshock-era vulnerability in GNU Bash that allows remote attackers to inject and execute arbitrary operating system commands by crafting a malicious environment. Because Bash is widely used as a system shell across Linux and Unix-based systems, exploitation can give an attacker full control over affected hosts without requiring authentication. Any internet-facing service that invokes Bash — such as CGI scripts or DHCP clients — is a potential entry point.</description><pubDate>Thu, 02 Oct 2025 00:00:00 GMT</pubDate><category>GNU</category><category>GNU Bash</category></item></channel></rss>