Cisco’s CVE-2026-20188 advisory describes a denial-of-service vulnerability in Cisco Crosswork Network Controller (CNC) and Cisco Network Services Orchestrator (NSO), first published on May 6, 2026 [1]. The issue is best understood as connection exhaustion: an unauthenticated remote attacker can send many connection requests, consume available connection resources, and make the affected platform stop responding normally [
1][
8].




