Cisco patches Crosswork and NSO DoS flaw that can force manual reboots
Cisco issued updates for a DoS vulnerability in CNC and NSO, requiring manual reboots for recovery if exploited.
Jason Kwon ·

Cisco has issued security updates for a denial-of-service (DoS) vulnerability affecting its Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO) platforms.
Tracked as CVE-2026-20188, the issue can be exploited remotely by an unauthenticated attacker to exhaust available connection resources and cause affected systems to become unresponsive.
Cisco said the flaw is caused by insufficient rate limiting on incoming network connections. If successfully exploited, recovery requires a manual reboot of the impacted system.
The company is urging customers to upgrade to fixed sosourcesware versions. Cisco’s Product Security Incident Response Team (PSIRT) said it is not aware of active exploitation.
Cisco also noted that other DoS issues in its products have been exploited in the past, in some cases requiring manual intervention to restore services.