logo

New Cisco Network Flaw Lets Remote Attackers Trigger DoS Attacks

ID: ae70c020-6504-5359-a45a-aa4a1b942084

STIX ID: report--ae70c020-6504-5359-a45a-aa4a1b942084

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-05-07

Date Updated: 2026-05-22

Author: AnuPriya

...
...

Cisco disclosed CVE-2026-20188, a high-severity connection-exhaustion vulnerability (CVSS 7.5) affecting Crosswork Network Controller (all releases up to 7.1) and Network Services Orchestrator (vulnerable: 6.3 and earlier; 6.4 -> upgrade to 6.4.1.3; 6.5 not affected). An unauthenticated remote attacker can flood connection requests to exhaust resources and render the management platform unresponsive, requiring a manual reboot to recover; there are no temporary workarounds and Cisco recommends immediate upgrades to the fixed versions. No public exploits or active malicious activity have been observed at time of the advisory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.