CVE-2026-5268: Ciena 6500 S-Series

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an attacker to read or modify system files.

Affected products

  • Ciena 6500 S-Series: up to and including R16.96
  • Ciena 6500 T-Series: up to and including R16.1
  • Ciena Cpl: up to and including R12.63
  • Ciena Pts: up to and including R16.1

Published 2026-07-06. Last modified 2026-07-08.