CVE-2026-5268: Ciena 6500 S-Series
Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.
An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an attacker to read or modify system files.
Affected products
- Ciena 6500 S-Series: up to and including R16.96
- Ciena 6500 T-Series: up to and including R16.1
- Ciena Cpl: up to and including R12.63
- Ciena Pts: up to and including R16.1
Published 2026-07-06. Last modified 2026-07-08.