81 New CVEs in Mobile Core Networks – 58 Already Patched After AI Findings

The researchers behind NTU's iFinder pipeline, which runs on Claude Opus 4.5, reported that precision rose from 28 to 75 percent compared with direct prompting.

Illustration: a corroded metal grid where most small holes are sealed with fresh weld seams while a few remain open – a metaphor for AI-driven discovery and patching of vulnerabilities.
Illustration
Gift article

81 New CVEs in Mobile Core Networks – 58 Already Patched After AI Findings

The researchers behind NTU's iFinder pipeline, which runs on Claude Opus 4.5, reported that precision rose from 28 to 75 percent compared with direct prompting. The details rest, for now, on Computer Weekly's reporting rather than the underlying Usenix paper.

Researchers at Nanyang Technological University (NTU) in Singapore have built a tool powered by a group of AI agents that found 84 vulnerabilities in the open source software that runs the core of 4G and 5G mobile networks. The findings were presented last month at the 35th Usenix Security Symposium in Baltimore, according to Computer Weekly's reporting on 22 September 2026.

The numbers behind the findings are concrete: the vulnerabilities are spread across seven open source implementations, including Open5GS, Free5GC and OpenAirInterface. The developers behind the projects have confirmed 83 of them, 81 have received CVE identifiers, and 58 are already patched. For operators and vendors of mobile core software, that is a concrete maintenance task already on the table.

The Flaw That Matters Most

The most severe vulnerability allows an attacker to redirect a subscriber's internet traffic to their own server. The flaw sits in the user plane function (UPF), the component that forwards subscriber traffic in a 5G network. The UPF did not verify that the packet detection rule IDs in an incoming session modification request were unique. An attacker can in principle inject a duplicate rule with higher priority and thereby send the victim's uplink traffic to themselves instead of to the internet.

The research team worked with an industry partner – who is not named – to reproduce this session hijacking flaw in two commercial 5G cores in controlled test environments. The findings therefore apply not just to open source, but to software of the same type used in commercial networks.

Lin Ziyu, a PhD student at NTU and the study's first author, described the worst case to Computer Weekly: "In the worst case, an attacker could trick the mobile network into sending a user's internet traffic straight to the attacker's server, allowing them to secretly monitor the victim's data," he said (Computer Weekly). Encryption offers limited protection, according to the reporting, because packet size, sequencing and timing can still reveal sensitive information.

How iFinder Works

The tool, called iFinder, audits core network code against the 3GPP specifications that define how mobile networks should behave. The pipeline consists of four agent roles:

  1. Preparation: One agent prepares the 3GPP documents and detection patterns that the rest of the pipeline works from.
  2. Code matching: A second agent searches for matches against those patterns in the source code.
  3. Triage: A third agent assesses each vulnerability candidate to separate real findings from mere suspicion.
  4. Exploitation: A fourth agent builds a proof-of-concept exploit, runs it in a test environment and revises it based on logs until it works – or the attempts run out.

Before the findings were reported to the maintainers, they went through human review. The entire pipeline runs on Anthropic's Claude Opus 4.5 model.

The Numbers That Show the Gain

The central question for anyone evaluating such tools is whether the agent structure actually contributes, or whether a well-prompted model can do the same. The researchers tested this against 22 known vulnerabilities. With direct prompting – the same detection patterns given straight to the model – eight of the flaws were detected, with 56 false positives, equivalent to 28 percent precision. iFinder caught 15 of the 22, with 12 false positives – a precision of 75 percent.

The exploitation agent showed an even clearer jump: it wrote working exploits for 19 of the 22 known flaws, versus eight for the model alone. Working exploits are the strongest evidence that a vulnerability is real, so this is not merely a matter of more alerts.

The difference in false positives – 12 versus 56 – suggests a possible mechanism behind the gain: the triage agent and the exploitation agent's requirement for a working proof-of-concept appear to filter out alerts that would otherwise end up as noise for overloaded maintainers. This is an interpretation of the numbers, not something the research team is quoted on.

The Root Cause: Trust Between Network Functions

Nearly all of the 84 vulnerabilities stem from the same problem, according to Wang Xiaofeng, a professor at NTU's College of Computing and Data Science (CCDS) and one of the project leads alongside Dong Wei: core functions accept messages from one another without verification. This is a legacy of the era when the core network sat in a physically isolated environment, where messages could be trusted to come from one's own equipment.

That means the flaws do not appear as isolated programming slips, but as a systemic pattern – and according to the reporting, some of the 5G flaws appear to have been inherited from 4G code. Tools that search against specifications rather than for known flaw signatures can therefore find variants of the same pattern across implementations.

Wang's recommendation to mobile operators is simple: work on the published CVEs. "If the problems persist, adversaries will exploit these vulnerabilities," he told Computer Weekly (Computer Weekly).

Open Questions

Several caveats should accompany the numbers. This story rests on Computer Weekly's reporting and quotes; the underlying Usenix paper has not been consulted, so the figures such as 84 vulnerabilities and the precision gain are not independently verified. The industry partner that reproduced the hijacking flaw in the commercial cores is not named, and it is unclear which four implementations beyond Open5GS, Free5GC and OpenAirInterface were tested. It is also unclear whether the 22 known flaws used to calibrate the pipeline are included in the 84 or are separate – and how the detection patterns were developed is not detailed in the sources. The project is funded by the Cyber Security Agency of Singapore under the country's national cybersecurity research and development programme.

These questions nonetheless do not change the main picture: an agent-based tool, evaluated against a known reference set with a documented precision gain, has found real flaws in software that mobile networks are actually built on – and most of the patching work remains.

AIMag.no
AIMag.no
The AIMag.no editorial team covers artificial intelligence, tools, research, and regulation.

Get the best of AI MAG in your inbox

News, analysis, and ideas at the intersection of AI and society.