Cisco warns CNC and NSO flaw can let remote attackers trigger denial-of-service attacks


Cisco has released security updates for a high-severity vulnerability in Crosswork Network Controller and Network Services Orchestrator that can let an unauthenticated remote attacker cause a denial-of-service condition.

The flaw is tracked as CVE-2026-20188 and has a CVSS score of 7.5. It affects the way Cisco CNC and Cisco NSO handle incoming network connections.

If attackers send a large number of connection requests to a vulnerable system, they can exhaust available connection resources. Cisco says affected systems can become unresponsive, disrupting legitimate users and dependent network services.

[TOC]

What Cisco disclosed

The vulnerability sits in the connection-handling mechanism of Cisco Crosswork Network Controller and Cisco Network Services Orchestrator. Cisco says the issue comes from inadequate rate limiting on incoming network connections.

An attacker does not need credentials to exploit the flaw. The attack also requires no user interaction, which makes exposure more serious for systems reachable from untrusted networks.

Successful exploitation does not lead to code execution or data theft based on Cisco’s advisory. The main impact is availability loss, but that can still create major disruption for network operations teams.

At a glance

ItemDetails
CVECVE-2026-20188
SeverityHigh
CVSS score7.5
Affected productsCisco Crosswork Network Controller and Cisco Network Services Orchestrator
Weakness typeUncontrolled resource consumption, CWE-400
Attack typeUnauthenticated remote denial of service
WorkaroundsNo Cisco workaround available
Exploitation statusNo public exploitation or malicious use reported by Cisco PSIRT

Why the vulnerability matters

Cisco CNC and NSO help organizations manage and automate complex network environments. These tools can sit close to important operational workflows, especially in large enterprises and service provider networks.

A denial-of-service attack against network management software can slow response work, block administrators, and disrupt automation that depends on the affected platform.

Cisco also says manual reboot is required to recover from the DoS condition. That raises the operational impact because teams may need direct intervention to restore normal service.

Affected Cisco CNC and NSO versions

ProductAffected releasesFixed release guidance
Cisco Crosswork Network Controller7.1 and earlierMigrate to a fixed release
Cisco Crosswork Network Controller7.2Not vulnerable
Cisco Network Services Orchestrator6.3 and earlierMigrate to a fixed release
Cisco Network Services Orchestrator6.4Upgrade to 6.4.1.3
Cisco Network Services Orchestrator6.5Not vulnerable

No workaround is available

Cisco says there are no workarounds that address CVE-2026-20188. That means administrators should not treat firewall rules, access controls, or monitoring as a full replacement for the fixed software.

Network restrictions may still reduce exposure as a general security practice, especially for management platforms. However, Cisco’s full remediation guidance points to upgrading to a fixed release.

The company found the vulnerability while resolving a Technical Assistance Center support case. Cisco PSIRT says it has not seen public announcements or malicious use of the flaw.

What administrators should do now

  • Identify all Cisco CNC and Cisco NSO deployments.
  • Check whether CNC systems run version 7.1 or earlier.
  • Check whether NSO systems run version 6.3 or earlier, or the affected 6.4 branch.
  • Upgrade Cisco NSO 6.4 deployments to 6.4.1.3 or later.
  • Migrate older CNC and NSO releases to a fixed release path.
  • Schedule a maintenance window because the issue can require reboot-based recovery if exploited.
  • Limit access to network management platforms to trusted administrative networks.
  • Monitor connection spikes and unexpected resource exhaustion until updates are complete.

Why DoS flaws in management tools need priority

Denial-of-service bugs can look less severe than remote code execution flaws, but the impact can still be serious. If attackers make network orchestration or management tools unavailable, administrators may lose visibility and control during an incident.

That risk grows in environments that depend on automation for provisioning, configuration changes, service orchestration, or multivendor network operations.

For affected Cisco customers, the safest response is to upgrade quickly and confirm that critical management services cannot be reached from unnecessary network paths.

FAQ

What is CVE-2026-20188?

CVE-2026-20188 is a high-severity denial-of-service vulnerability in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator.

Can attackers exploit it without logging in?

Yes. Cisco says an unauthenticated remote attacker can exploit the flaw by sending a large number of connection requests to an affected system.

Does the flaw allow remote code execution?

No. Cisco’s advisory describes the impact as denial of service. The affected systems can become unresponsive and may require a manual reboot.

Are there any workarounds?

No. Cisco says there are no workarounds that address this vulnerability. Customers need to upgrade to fixed software.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages