Executive Summary
In July 2026, researchers from Singapore's Nanyang Technological University disclosed 84 security vulnerabilities in 4G and 5G core networks, collectively termed implicit trust errors (iTrue). These flaws, found in open-source LTE/5G core implementations, stem from unchecked trust between core network functions, enabling attackers to execute denial-of-service (DoS) attacks and session hijacking by exploiting signaling interfaces like GTP-C and PFCP. The vulnerabilities affect widely used open-source LTE/5G cores, including Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF.
The study highlights the risks associated with cloud-native deployments, where traditional physical isolation is replaced by software-defined architectures, increasing the attack surface. The researchers developed an LLM-assisted system, iFinder, to identify these vulnerabilities, emphasizing the need for rigorous validation and resource checks in core network components to prevent such exploits.
Why This Matters Now
The transition to cloud-native 5G networks has expanded the attack surface, making implicit trust errors a critical concern. Addressing these vulnerabilities is urgent to prevent potential DoS attacks and session hijacking that could disrupt services and compromise user data.
Attack Path Analysis
An attacker exploits vulnerabilities in the 4G/5G core network to gain unauthorized access, escalates privileges to control network functions, moves laterally to compromise additional components, establishes command and control channels, exfiltrates sensitive data, and causes service disruptions.
Kill Chain Progression
Initial Compromise
Description
The attacker exploits unprotected control procedures in the 4G/5G core network to gain unauthorized access.
Related CVEs
CVE-2026-10157
CVSS 7.3An authentication bypass vulnerability in Open5GS's NGAP PathSwitchRequest message handler allows unauthenticated remote attackers to gain unauthorized access to 5G network functions.
Affected Products:
Open5GS Open5GS – <= 2.7.6
Exploit Status:
proof of conceptCVE-2026-4240
CVSS 7.5A denial of service vulnerability in Open5GS's CCA Handler allows remote attackers to crash the Session Management Function (SMF) by sending a Credit-Control-Answer (CCA) message with an unknown Diameter session.
Affected Products:
Open5GS Open5GS – <= 2.7.6
Exploit Status:
proof of concept
MITRE ATT&CK® Techniques
Network Denial of Service
Network Denial of Service: Malicious Packets To Network Functions
Endpoint Denial of Service: DOS A UE Via gNB Or NF Signaling
Network Denial of Service: Shared Slice Common Control Network Function Resource Exhaustion
Network Denial of Service: Flooding Core Network Component
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Denial of Service Protection
Control ID: SC-5
PCI DSS 4.0 – System Security Vulnerabilities Management
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
CISA ZTMM 2.0 – Network and Environment
Control ID: Pillar 3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Direct exposure to 4G/5G core network vulnerabilities enabling DoS attacks and session hijacking, requiring immediate network infrastructure security upgrades and traffic encryption.
Banking/Mortgage
Critical risk from session hijacking vulnerabilities in mobile banking services, threatening encrypted traffic security and requiring enhanced east-west traffic monitoring compliance.
Health Care / Life Sciences
Mobile health systems vulnerable to network infrastructure attacks compromising HIPAA compliance, requiring zero trust segmentation and encrypted traffic for patient data protection.
Government Administration
National security implications from widespread 4G/5G vulnerabilities affecting secure communications, demanding multicloud visibility controls and threat detection for critical infrastructure protection.
Sources
- Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flawhttps://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.htmlVerified
- CVE-2026-10157: Open5GS NGAP Authentication Bypass Vulnerability – 5G Core Network Riskhttps://sec.co/vulnerabilities/cve-2026-10157Verified
- CVE-2026-4240: Open5GS CCA Handler DoS Vulnerabilityhttps://www.sentinelone.com/vulnerability-database/cve-2026-4240/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to exploit vulnerabilities, escalate privileges, move laterally, establish command and control channels, exfiltrate data, and disrupt services within the 4G/5G core network.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access would likely be constrained, reducing the scope of unauthorized entry points within the network.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, limiting their control over critical network components.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely be constrained, reducing their ability to compromise additional network functions and user equipment.
Control: Multicloud Visibility & Control
Mitigation: The attacker's establishment of command and control channels would likely be constrained, reducing their ability to maintain persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely be constrained, reducing the volume of sensitive data leaving the network.
The attacker's ability to cause widespread service disruptions would likely be constrained, reducing the overall impact on network availability.
Impact at a Glance
Affected Business Functions
- Network Operations
- Customer Connectivity
- Service Delivery
Estimated downtime: 3 days
Estimated loss: $500,000
Potential exposure of user session data and network configuration information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Encrypted Traffic (HPE) to protect data in transit and prevent unauthorized access.
- • Deploy East-West Traffic Security to monitor and control lateral movement within the network.
- • Utilize Zero Trust Segmentation to enforce least privilege access and limit the attack surface.
- • Enhance Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Establish Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and command and control communications.



