New Cisco Network Vulnerability Let Remote Attacker Cause DoS Attack
ID: 86e61c68-85f6-5b2f-b140-bdfcf61f9ca9
STIX ID: report--86e61c68-85f6-5b2f-b140-bdfcf61f9ca9
Feed Name: cybersecurityNews.com
Cisco has published an advisory for CVE-2026-20188 (CVSS 7.5), a resource-exhaustion (CWE-400) flaw in Crosswork Network Controller and Network Services Orchestrator that permits unauthenticated remote actors to create a disruptive Denial-of-Service by flooding connection requests; affected releases include CNC 7.1 and earlier and multiple NSO branches (patched in NSO 6.4.1.3 and fixed in 6.5+; CNC fixed in 7.2). There are no available workarounds and recovery requires manual reboot, so Cisco urges immediate upgrades to the fixed releases; PSIRT has not observed exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
