PatchSiren cyber security CVE debrief
CVE-2026-75439 Free5GC CVE debrief
CVE-2026-75439 debrief based on the supplied source corpus. The CVE record was published on 2026-09-04T21:17:25.583Z and has not been modified since then. Free5GC v.4.2.2 has a denial-of-service vulnerability in the UPF component. Defenders should assess potential exposure and verify configurations to prevent denial-of-service attacks. The CVSS score is 7.5 with a HIGH severity rating. The vulnerability allows a remote attacker to cause a denial of service via the UPF component. Limited information is available about the vulnerability.
- Vendor
- Free5GC
- Product
- Free5GC
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-04
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-09-04
- Advisory updated
- 2026-09-14
Who should care
Defenders responsible for Free5GC deployments, especially those using UPF components, should assess potential exposure and verify configurations to prevent denial-of-service attacks.
Why it matters
CVE-2026-75439 is a denial-of-service vulnerability in Free5GC v.4.2.2, affecting the UPF component. Defenders should verify exposure, review configurations, and monitor systems to prevent and respond to potential attacks.
- Potential denial-of-service attacks against Free5GC deployments
- Verification of UPF component usage and configurations
- Monitoring for unusual activity or outages in Free5GC systems
Technical summary
The CVE record describes a denial-of-service vulnerability in Free5GC v.4.2.2, affecting the UPF component. The CVSS score is 7.5 with a HIGH severity rating. The vulnerability allows a remote attacker to cause a denial of service via the UPF component. The vulnerability has not been modified since its publication on 2026-09-04T21:17:25.583Z. Defenders should prioritize verifying exposure in Free5GC deployments, especially those using UPF components, and assess potential denial-of-service risks. Limited information is available about the vulnerability.
Defensive priority
Defenders should prioritize verifying exposure in Free5GC deployments, especially those using UPF components, and assess potential denial-of-service risks.
Recommended defensive actions
- Verify Free5GC deployments for UPF component usage and assess potential exposure
- Review and update Free5GC configurations to prevent denial-of-service attacks
- Monitor Free5GC systems for unusual activity or outages
- Perform a thorough review of UPF component usage
- Check for any existing mitigations or patches
- Consider implementing compensating controls for exposed systems
- Track exceptions and retest remediated assets
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability, with a CVSS score of 7.5 and a HIGH severity rating. The vulnerability affects Free5GC v.4.2.2 and allows a remote attacker to cause a denial of service via the UPF component. Evidence is limited to CVE and NVD data. Defenders should verify exposure and review configurations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75439 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75439
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75439 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75439
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://gist.github.com/hackeryounow/0f434c03008462e6eec3b43ed3cd12d8
-
Source reference
Unverified legacy reference
URL: https://github.com/free5gc/free5gc/issues/1059
-
Source reference
Unverified legacy reference
URL: https://github.com/free5gc/free5gc/issues/1059.https://github.com/free5gc/go-upf/pull/97
-
Source reference
Unverified legacy reference
URL: https://github.com/free5gc/go-upf/pull/97
-
Source reference
Unverified legacy reference
URL: https://github.com/hackeryounow/5GCVulDB/tree/main/CVE-2026-75439
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.