VU#615987: Missing IPsec Integrity Protection for IMS SIP Signaling in Verizon VoLTE Deployments
2026-06-02T20:52:16Z•55e74ff684785b52391c9228a2eda7849b38b991413c207ce73f3a3bc314b458
BYOVDIMSIPsecSAMLSIPappsmithauthentication-bypasscall-hijackingcasdoorcollibradriverintegrity-bypasslinux-kernel','dirty-frag'','fragmentation','memory-corruption'mfa-bypassmissing-access-controlpath-traversalrceremote-code-executionsql-autocompletestored-xssverizonvoLTEwindows-kernelxsszip-slip
What happened
CERT/CC vulnerability notes feed summarizing multiple distinct high-impact issues across carriers, enterprise software, open-source projects, and OS kernels. Key entries: Verizon VoLTE IMS SIP signaling was observed without negotiated IPsec ESP integrity protection (CVE-2026-10629), allowing interception/modification of SIP signaling and enabling call hijack or emergency-call misrouting. Appsmith stored XSS in the SQL editor autocomplete (CVE-2026-7299) allows developer-level attackers to execute JavaScript in other workspace members’ browsers. Collibra Platform Agent exposes privileged RESTs/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 55e74ff684785b52391c9228a2eda7849b38b991413c207ce73f3a3bc314b458
- Enrichment time
- 2026-06-02T20:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.