Skip to main content

Share story

Security

New Cisco DoS flaw requires manual reboot to revive devices

New Cisco DoS flaw requires manual reboot to revive devices Image: Primary
Cisco released security updates to fix a Crosswork Network Controller and Network Services Orchestrator denial-of-service vulnerability that requires manually rebooting targeted systems for recovery. The software helps large enterprises and service providers manage multivendor networks with automation and orchestrate network devices and resources. Tracked as CVE-2026-20188, the high-severity flaw stems from inadequate rate limiting on incoming network connections and can be exploited remotely by unauthenticated actors through low-complexity attacks. A successful exploit could allow an attacker to exhaust available connection resources, causing the systems to become unresponsive and resulting in a denial-of-service condition. Cisco explained that a manual reboot of the system is required to recover from this condition. The company strongly recommends that customers upgrade to the fixed software indicated in its advisory. Cisco's Product Security Incident Response Team is not aware of ongoing exploitation of the vulnerability. The flaw has not been exploited in the wild yet. Cisco has previously patched other denial-of-service vulnerabilities that were exploited in attacks, including two flaws in its ASA and FTD firewalls that forced devices into reboot loops, issues in Secure Email appliances that required manual intervention to recover, and a flaw that crashed the Border Gateway Protocol process on IOS XR routers.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Infrastructure Capital
Infrastructure Capital

Clastix raises €2.9 million for Kubernetes infrastructure software

Italian infrastructure software company Clastix has raised €2.9 million in its first external funding round, led by CDP Venture Capital with participation from Mistral and Vertis SGR. Clastix plans to use the seed capital for prod...

AI Science
AI Science

DeliveryGym study shows gains in simulated courier planning

Researchers introduced DeliveryGym, a three-dimensional environment that trains AI agents to plan across a full courier shift, where one delivery can use time, energy or money needed for later orders. In tests across six models an...

AI Science
AI Science

Preprint reports gains from grounding game-coaching AI in live state

Researchers report that rules tying an AI game coach to current match and session data raised its turn-level factual accuracy to 96.7%, from 61.1% for a prompting baseline and 69.8% for another agent design. Session-level accuracy...