Researchers Found 84 Vulnerabilities in 5G Networks
Nanyang Technological University discovered flaws in mobile core software during an August 2026 study.
Updated on Sept. 22, 2026 in Cybersecurity

Live Poll
Do you trust the security of the software powering your national mobile and internet networks?
Researchers identified 84 vulnerabilities within open source software controlling 4G and 5G mobile networks. The findings, presented in August 2026, include a critical flaw capable of hijacking subscriber internet sessions.
Why it matters
The vulnerabilities stem from legacy trust assumptions where network functions accept messages without verification. These risks have expanded as software-defined and cloud-based components replace physically isolated network environments.
The study analyzed seven implementations, including Open5GS, free5GC, and OpenAirInterface, using agentic AI to check code against 3GPP specifications. Researchers confirmed 83 flaws, with 81 receiving official Common Vulnerabilities and Exposures identifiers.
The players
Nanyang Technological University
This is a major public autonomous research university in Singapore that led the vulnerability study.
Cyber Security Agency of Singapore
This is the national authority on cybersecurity in Singapore that provided funding for the research project.
The details
The flaws allow attackers to inject high-priority rules to redirect uplink traffic, enabling session hijacking. Researchers verified this exploit in two separate commercial 5G core network environments.
Timeline
August 2026: The research findings were presented at the Usenix Security Symposium.
The Tech Race
This research highlights the security challenges inherent in shifting from isolated hardware to cloud-based, software-defined networks. By auditing code against 3GPP specifications, the findings serve as a critical check on the rapid deployment of global mobile infrastructure.
While developers work to patch these flaws, the discovery underscores potential risks to user session integrity on mobile networks. Continued software updates to network infrastructure are necessary to mitigate the threat of traffic redirection.
The takeaway
Security research demonstrates that cloud-based network shifts require more rigorous automated testing against established standards. Users should ensure their devices and network providers remain updated to benefit from ongoing security patches.
Further reading
Learn more about the latest developments in Cybersecurity.
Live Poll
Do you trust the security of the software powering your national mobile and internet networks?







