Open5GS up to version 2.7.6 contains a remotely triggerable denial-of-service condition in the SGWC component. The issue is in the function sgwc_s5c_handle_modify_bearer_response within src/sgwc/s5c-handler.c, where crafted/manipulated input related to handling a Modify Bearer Response can cause the SGWC process to crash or otherwise become unavailable, resulting in service disruption. A public exploit is reported to be available. The issue is flagged as already fixed upstream via patch/commit b19cf6a.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose: a Python-based “mass exploiter” for CVE-2026-1522, described as an unauthenticated arbitrary file upload in a WordPress plugin path using /wp-admin/admin-ajax.php with action=wfmw_upload_file, aiming to achieve RCE by uploading a PHP payload and then verifying execution. Structure: - CVE-2026-1522.py: main exploit/scanner. Implements URL normalization, reachability checks (HTTP HEAD and raw TCP connect), multithreaded processing via ThreadPoolExecutor, result collection/aggregation, and reporting/statistics. TLS verification is disabled (verify=False) to improve reach across misconfigured HTTPS. - shells.php: minimal PHP marker payload (prints “W.P.E.F|Poloss”). - wpef.txt: PHP marker/info template (server/PHP info + “W.P.E.F” verification marker), likely used to confirm successful upload and execution. - README.md: usage instructions, claimed detection layers, and the stated exploit request format (multipart POST to admin-ajax.php). - url.txt: example target list entry. - Baner.txt: ASCII art banner. Exploit capabilities (as evidenced by code/README): - Bulk target ingestion from a file, normalization of hostnames/URLs, and concurrent scanning/exploitation. - Network reachability probing (HEAD request; fallback TCP connect to 80/443 or explicit port). - Attempts unauthenticated file upload to WordPress AJAX endpoint (per README), then performs post-upload discovery and validation by requesting the uploaded PHP file and checking for a marker. - Produces output files listing vulnerable and “verified” vulnerable targets and prints colored per-thread status messages. Notable observables: - Primary target endpoint: /wp-admin/admin-ajax.php with action=wfmw_upload_file. - Included payload markers: “W.P.E.F|Poloss” and “W.P.E.F”. Limitations of this analysis: the provided CVE-2026-1522.py content is truncated, so exact upload paths, parameter names beyond the README, and the precise discovery logic for locating the uploaded file cannot be fully enumerated from the snippet; however, the repository clearly contains an operational mass exploitation tool rather than a pure detector.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.