Security Advisory

CVE-2026-5268

9.1
CRITICAL

Vulnerability Description

An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allows a remote, unauthenticated attacker to bypass security controls and gain unauthorized access to the underlying filesystem. Successful exploitation could allow an attacker to read or modify system files.
Published Date July 6, 2026
Official Source NIST NVD Advisory