CVE-2026-15720: OPEN5GS

High severity, CVSS 8.6. EPSS: 0.5% chance of exploitation in the next 30 days.

In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.

Affected products

  • OPEN5GS OPEN5GS: up to and including 2.7.7

Published 2026-07-14. Last modified 2026-07-15.