SEPTEMBER 12, 2026
Live Feed
Back to database
Case File

CVE-2026-15720

HIGH · CVSS 8.6 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Open5GS versions up to 2.7.7 are vulnerable to a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler, which can lead to a subscriber-wide denial of service. Organizations using this software should prioritize patching to mitigate the risk of service disruption. This vulnerability poses a significant threat to network availability and should be addressed promptly by service providers relying on Open5GS.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15720
Severity
HIGH
CVSS
8.6
EPSS
0.37%

Original NVD Description

In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.