Cisco security patch release for CVE-2026-20188
Security Patch Release
Summary
Hide ▲
Show ▼
Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO) that can take unpatched systems offline. Unauthenticated remote attackers can abuse the flaw with low-complexity attacks by exhausting connection resources. Successful exploitation can leave devices and dependent services unresponsive until a manual reboot. Cisco says customers should upgrade to the fixed software; CNC 7.2 and NSO 6.4.1.3/6.5 are listed as not vulnerable.
Related Happenings
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/Mitigation
H score46
First: 15.07.2026 17:07
Last: 15.07.2026 17:07
Sources 1
About this happening:
CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA Microsoft SharePoint hardening guidance for exploited zero-days
Advisory/MitigationAbout this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector Action
H score77
First: 15.07.2026 12:44
Last: 15.07.2026 12:44
Sources 1
About this happening:
CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
CISA BOD 26-04 SharePoint remediation deadline
Public Sector ActionAbout this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...
SAP NetWeaver Application Server ABAP SICF workaround for CVE-2026-44747
Advisory/Mitigation
H score40
First: 14.07.2026 21:17
Last: 14.07.2026 21:17
Sources 1
About this happening:
SAP NetWeaver Application Server ABAP customers now have a temporary workaround for CVE-2026-44747 that can reduce exposure to memory corruption. The mitigation disabl...
SAP NetWeaver Application Server ABAP SICF workaround for CVE-2026-44747
Advisory/MitigationAbout this happening: SAP NetWeaver Application Server ABAP customers now have a temporary workaround for CVE-2026-44747 that can reduce exposure to memory corruption. The mitigation disabl...
CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server
Public Sector Action
H score35
First: 26.06.2026 22:43
Last: 26.06.2026 22:43
Sources 1
About this happening:
CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...
CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server
Public Sector ActionAbout this happening: CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...
Cisco security patch release for CVE-2026-20245
Security Patch Release
H score38
First: 25.06.2026 00:29
Last: 25.06.2026 00:29
Sources 1
About this happening:
Cisco released security updates for Cisco Catalyst SD-WAN after CVE-2026-20245 was linked to root-level command execution, and customers were told to move to fixed sof...
Cisco security patch release for CVE-2026-20245
Security Patch ReleaseAbout this happening: Cisco released security updates for Cisco Catalyst SD-WAN after CVE-2026-20245 was linked to root-level command execution, and customers were told to move to fixed sof...
Timeline
-
06.05.2026 21:06 2 articles · 2mo ago
Cisco releases fixes for CVE-2026-20188 in CNC and NSO
Mitigation Patch UpdateCisco released security updates for CVE-2026-20188, a high-severity denial-of-service flaw in Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO) caused by inadequate rate limiting on incoming network connections. Unauthenticated remote attackers can exhaust connection resources, leave Cisco CNC and Cisco NSO unresponsive for legitimate users and dependent services, and recovery requires a manual reboot. Cisco advises customers to upgrade to the fixed software, with CNC 7.2 and NSO 6.4.1.3/6.5 listed as not vulnerable.
Show sources
- New Cisco DoS flaw requires manual reboot to revive devices — www.bleepingcomputer.com — 06.05.2026 21:06
- New Cisco DoS flaw requires manual reboot to revive devices — www.bleepingcomputer.com — 06.05.2026 21:06