AI agents expose 5G core security risks for telecom operators

  • AI agents uncovered 84 new flaws in 4G and 5G cores, speeding telecom vulnerability discovery
  • Internal 5G interfaces are now attack surfaces and need zero-trust protections
  • A validated flaw could hijack subscriber traffic, raising risks for commercial 5G networks

New research challenges one of telecom’s longest-standing assumptions: that the mobile core is safe because it is internal. Researchers at Nanyang Technological University used a multi-agent AI system called iFinder to find 84 previously unknown vulnerabilities in several widely deployed 4G and 5G network core implementations. 

In a cloud-native world, “internal” no longer means physically isolated. Misconfigured clusters, shared infrastructure, compromised workloads or overly broad network access could give attackers a path to interfaces that were never designed to face hostile traffic. 

This is a preview of the next security race. If researchers can use AI agents to discover and exploit telecom flaws at scale, adversaries can do the same.  

Top takeaways from the report

AI is accelerating telecom vulnerability discovery 

Researchers used iFinder, a multi-agent LLM system, to uncover 84 previously unknown vulnerabilities across seven 4G and 5G core implementations; 83 were confirmed and 81 received CVEs. That signals a new pace of security discovery for telecom infrastructure — one that operators and vendors may not be prepared to match with current patch cycles.

Internal 5G core interfaces are now real attack surfaces 

Interfaces like N4/PFCP and S11/S5/GTP-C should no longer be treated as protected simply because they are “internal.” The report argues they need the same kind of authentication, segmentation and message validation applied to internet-facing systems 

The most concrete risk is subscriber traffic hijacking 

The standout flaw is CVE-2026-8233, a PFCP session hijacking vulnerability that could allow an attacker with access to a UPF’s internal interface to redirect a subscriber’s uplink traffic. The attack was validated against two commercial 5G core deployments, which makes this more than a theoretical open-source issue.

UPFs and gateways deserve immediate scrutiny 

The majority of findings were concentrated in PFCP/User Plane Function and GTP-C/Serving Gateway code. Operators should prioritize patch verification and exposure audits for those components, while vendors should treat session-state validation, identifier checks and resource limits as urgent engineering priorities.

Vendors need to redesign for zero trust, not bolt on fixes 

The findings point to specification-level and architecture-level trust assumptions, not just sloppy coding. Vendors should bake in mutual authentication, strict input validation, state-invariant checks and bounded resource allocation across internal signaling paths.

Read more about AI agents and cybersecurity

NGMN: Agentic AI needs guardrails before it can run telco networks

CrowdStrike: Companies give AI agents keys to the kingdom. That's a security disaster.

CrowdStrike debuts threat-hunting AI agents