logo

New Cisco Network Vulnerability Let Remote Attacker Cause DoS Attack

ID: 86e61c68-85f6-5b2f-b140-bdfcf61f9ca9

STIX ID: report--86e61c68-85f6-5b2f-b140-bdfcf61f9ca9

Feed Name: cybersecurityNews.com

Threat Score
68/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Abinaya

...
...

Cisco has published an advisory for CVE-2026-20188 (CVSS 7.5), a resource-exhaustion (CWE-400) flaw in Crosswork Network Controller and Network Services Orchestrator that permits unauthenticated remote actors to create a disruptive Denial-of-Service by flooding connection requests; affected releases include CNC 7.1 and earlier and multiple NSO branches (patched in NSO 6.4.1.3 and fixed in 6.5+; CNC fixed in 7.2). There are no available workarounds and recovery requires manual reboot, so Cisco urges immediate upgrades to the fixed releases; PSIRT has not observed exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.