CVE-2026-2523Disclosure(open5gs / open5gs)

MEDIUMCVSS 7.5 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch open5gs open5gs systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function smf_gn_handle_create_pdp_context_request of the file /src/smf/gn-handler.c of the component SMF. The manipulation results in reachable assertion. It is possible to launch the attack remotely. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-617

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • open5gs

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-02-16); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
open5gs

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-16: 2Mentions · 2026-03-19: 1Active Exploitation · 2026-03-19: 1Patch / Workaround · 2026-03-19: 1Technical Details · 2026-02-16: 2Technical Details · 2026-03-19: 102-1603-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-162
Disclosure2
2026-03-191
General1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2523 A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function smf_gn_handle_create_pdp_context_request of the file /src/smf/gn-handler.c of … https://www.cve.org/CVERecord?id=CVE-2026-2523

    Post summary

    CVE-2026-2523 is a disclosed vulnerability affecting Open5GS up to version 2.7.6, specifically the smf_gn_handle_create_pdp_context_request function; no PoC, exploit, or patch information is provided.

    00020631
    56.4K followersView on X
  • TheDarkForge@DarkForgeNews
    General

    [BREAKING] Reported Zero-Days in CrowdStrike, Okta, Microsoft, VMware—Claims of 1,200+ Orgs Breached Unsubstantiated Claims of Russian APT29 exploiting a zero-day in CrowdStrike Falcon Sensor (CVE-2026-XXXX), compromising 1,200 organizations across 47 countries—including 320 Fortune 500 firms and 15 US government agencies—lack supporting evidence from credible sources. The alleged flaw enabled privilege escalation and data exfiltration; purported CrowdStrike patches at 14:00 UTC on March 18 isolated 85% of incidents within four hours, with initial remediation costs of $450 million. This would mark the first confirmed Falcon exploitation since 2024, amid heightened Russian cyber operations post-Ukraine invasion, exposing risks in cloud EDR platforms. Okta disclosed breaches in the past, including a 2023 support system incident exposing session tokens from HAR files for ~18,000 customers, but no verified March 2026 zero-day in Auth0 exposing 18 million tokens affecting 4.2 million users. Past tokens remained valid post-exposure; ~12% revoked in prior cases, with risks of account takeovers bypassing MFA. Multiple Okta incidents over years spotlight federated SSO weaknesses, though 2026 GDPR tightenings remain prospective—potential fines could exceed €200 million. Microsoft's March 18 Patch Tuesday fixed 127 vulnerabilities, including critical Exchange Server zero-day CVE-2026-2523 (CVSS 9.8) exploited in-the-wild since March 15 by five groups, two state-linked—no sources confirm this specific event or hits to 68% of global on-prem Exchange servers with 2,400 systems emergency-patched. Largest update since 2024; legacy Exchange persists despite Microsoft 365 migrations, leaving SMEs exposed. North Korea's Lazarus Group linked to past attacks. VMware vCenter Server RCE (CVE-2026-1170) saw purported mass exploitation by Iranian UNC2448 actors, with 850 instances hit—mostly Middle East and US healthcare/finance. Unauthenticated code execution allegedly affected 40% of victims, exposing over 10,000 VMs each. Broadcom reportedly patched March 18; legacy vCenter lingers in 55% of datacenters despite end-of-support. TikTok faces ongoing EU scrutiny under GDPR for minors' consent and data transfers, but no confirmed €1.2 billion fine from France's CNIL on March 19—previous record fine was €345 million in 2023. Covers prior periods, impacting millions of EU minors; ByteDance scrutiny continues on recommendation AI, with potential CJEU appeal. Total economic impact and coordinated 24-hour barrage by Russia, China, Iran, North Korea unverified. CISA/NSA lead US responses to real incidents; firms like Cloudflare/Google aided past Okta mitigation; Mandiant analyzes threats. Enterprise risks: EDR users assess single-agent reliance—breakout times under minutes per threat reports. SSO forces token rotation, straining IT. On-prem Exchange shops rush patches or face RCE. Legacy vCenter exposes datacenters. GDPR signals Big Tech consent requirements. Competitive notes: Rapid response in verified cases underscores EDR strengths, but zero-days prove no platform immune. Microsoft pushes M365 post-Exchange risks; Okta scrutiny boosts rivals like Ping Identity. VMware's Broadcom era accelerates migrations to Nutanix/AWS. Regulators enforce GDPR—fines pressure platforms pre-2027 AI rules. Next steps: Shrink patch windows to hours. MFA insufficient—adopt zero-trust identity. EDR/SSO vendors face audits; Fortune 500s recalibrate budgets. Monitor state-linked escalations tied to geopolitics. Enterprises: inventory Exchange/vCenter; rotate tokens. — THE FORGE'S WEIGHT Vendors tout ironclad detection—CrowdStrike isolated 85% fast in claims, yet APT29 allegedly pierced Falcon first. Platforms promise seamless protection; zero-days expose single points where cloud dependency meets state precision. Enterprises demand breach-proof tech, regulators enforce consent—each incident widens the gap between marketed invulnerability and deployed reality. Does rapid response suffice when actors compress timelines to minutes, or does it merely reset the board?

    Post summary

    The post discusses alleged zero‑day exploitation across several vendors, notes patch releases, cites possible in‑the‑wild attacks, and highlights the lack of evidence supporting the claims.

    0000058
    12 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2523 📊 Severity: 5.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2523 #CVE-2026-2523 #CVE #Medium #CyberSecurity #InfoSec https://t.co/O9LJKc9Dfl

    Post summary

    A concise CVE alert for CVE-2026-2523, noting a medium severity (CVSS 5.3) with no further technical, exploitation, or mitigation details.

    0000034
    56 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopen5gsopen5gs---

Explore more