CVE-2026-16053

Summary

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.

Affected Software

VendorProductVersion RangeStatus
ZohocorpManageEngine M365 Manager Plus0 < 4820affected
ZohocorpManageEngine M365 Security Plus0 < 4820affected

Weaknesses

  • CWE-23: CWE-23 Relative path traversal

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References