New Cisco Network Flaw Lets Remote Attackers Trigger DoS Attacks
ID: ae70c020-6504-5359-a45a-aa4a1b942084
STIX ID: report--ae70c020-6504-5359-a45a-aa4a1b942084
Feed Name: Cyber Press
Cisco disclosed CVE-2026-20188, a high-severity connection-exhaustion vulnerability (CVSS 7.5) affecting Crosswork Network Controller (all releases up to 7.1) and Network Services Orchestrator (vulnerable: 6.3 and earlier; 6.4 -> upgrade to 6.4.1.3; 6.5 not affected). An unauthenticated remote attacker can flood connection requests to exhaust resources and render the management platform unresponsive, requiring a manual reboot to recover; there are no temporary workarounds and Cisco recommends immediate upgrades to the fixed versions. No public exploits or active malicious activity have been observed at time of the advisory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
