CVE-2026-7535Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Open5GS up to 2.7.7. This affects the function amf_namf_comm_handle_registration_status_update_request in the library /lib/app/ogs-init.c of the file /namf-comm/v1/ue-contexts/{ueContextId}/transfer-update. Performing a manipulation of the argument ueContextId results in denial of service. The attack can be initiated remotely. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-404

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-01); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-05-01: 3Mentions · 2026-05-04: 2Technical Details · 2026-05-01: 2Technical Details · 2026-05-04: 205-0105-04
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-013
Disclosure3
2026-05-042
Disclosure2
Full discourse5 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7535 A vulnerability was found in Open5GS up to 2.7.7. This affects the function amf_namf_comm_handle_registration_status_update_request in the library /lib/app/ogs-init.c o… https://www.cve.org/CVERecord?id=CVE-2026-7535 ----- Traducción: CVE-2026-7535 Se … http://infoflow.cloud`

    Post summary

    A new vulnerability, CVE-2026-7535, has been documented in Open5GS affecting a specific function; no exploit, patch, or active use has been reported.

    0000028
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7535 A vulnerability was found in Open5GS up to 2.7.7. This affects the function amf_namf_comm_handle_registration_status_update_request in the library /lib/app/ogs-init.c o… https://www.cve.org/CVERecord?id=CVE-2026-7535

    Post summary

    The snippet announces CVE-2026-7535 affecting Open5GS up to 2.7.7, detailing the impacted function but offering no information on exploitation, patches, or fixes.

    00000191
    57.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7535 📊 Severity: 4.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7535 #CVE-2026-7535 #CVE #Medium #CyberSecurity #InfoSec https://t.co/KkzRbReEjB

    Post summary

    The tweet announces the new CVE-2026-7535 with a medium severity score, directing readers to the NVD entry for details.

    0000032
    151 followersView on X
  • SystemTek - Technology news website@SystemTek_UK
    Disclosure

    Open5GS denial of service vulnerability (CVE-2026-7535) #CyberSecurity #Open5GS #RemoteCodeExecutionVulnerability https://www.systemtek.co.uk/2026/05/open5gs-denial-of-service-vulnerability-cve-2026-7535/ https://t.co/Gw7Yib6RMY

    Post summary

    The tweet announces a newly disclosed denial-of-service vulnerability (CVE-2026-7535) in Open5GS, with no evidence of an active exploit, PoC, or patch information provided.

    0000033
    1.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7535 Denial of Service in Open5GS Up to 2.7.7 via UeContextId Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7535

    Post summary

    The entry announces a Denial of Service vulnerability (CVE-2026-7535) in Open5GS up to version 2.7.7 caused by UeContextId manipulation, with no PoC, exploit, or patch details provided.

    0000035
    4.0K followersView on X

Explore more