Briefing

New Cisco DoS flaw requires manual reboot to revive devices

security
by Sergiu Gatlan · CVE-2022-20653 CVE-2024-20401 CVE-2025-20115 CVE-2025-20333 CVE-2025-20362 CVE-2026-20188

Upgrade CNC to 7.2 or later and NSO to 6.5 or later to patch CVE‑2026‑20188 and eliminate the DoS risk.

What to do now

Upgrade CNC to 7.2 or later and NSO to 6.5 or later to patch CVE‑2026‑20188 and eliminate the DoS risk.

Summary

On May 6, 2026 Cisco issued a security advisory for a high‑severity denial‑of‑service flaw (CVE‑2026‑20188) that exploits inadequate rate limiting on incoming connections in its Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO).

The vulnerability allows unauthenticated attackers to exhaust connection resources, causing CNC and NSO to become unresponsive and requiring a manual reboot to recover.

Cisco recommends upgrading to the fixed releases: CNC 7.2 or later (7.1 and earlier are vulnerable) and NSO 6.5 or later (6.3 and earlier, 6.4, 6.4.1.3 are vulnerable).

The advisory notes that no exploitation has been observed in the wild yet, but Cisco has previously patched similar DoS bugs that were actively exploited.

The affected releases are listed in detail, and Cisco stresses that the only recovery method for a crash is a manual reboot until the patch is applied.

This incident underscores the importance of timely patching for network orchestration software to prevent service disruption.

Key changes

  • CVE‑2026‑20188 exploits inadequate rate limiting on incoming connections in Cisco CNC and NSO.
  • Affected CNC releases: 7.1 and earlier; fixed in 7.2.
  • Affected NSO releases: 6.3 and earlier, 6.4, 6.4.1.3; fixed in 6.5.
  • Manual reboot is required to recover from a DoS condition.
  • Cisco recommends upgrading to the fixed releases to eliminate the vulnerability.
  • No exploitation has been observed in the wild yet, but similar DoS bugs were previously exploited.

Affects

enterprise internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting