CISA issues update on missing IPsec integrity for Verizon IMS SIP signaling
CISA’s update on CVE-2026-10629 says Verizon IMS SIP signaling for VoLTE omits IPsec ESP integrity, leaving REGISTER, INVITE, MESSAGE, BYE, and UPDATE traffic unprotected. The advisory cites expected 3GPP TS 33.203 and GSMA IR.92 behavior and notes Verizon’s “currently available” integrity support statement for later rollout.