What is CVE-2026-16053?
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected by an authenticated Path Traversal vulnerability in the Exchange Online backup module. This could allow an authenticated malicious user to perform limited operations on the server. It is strongly recommended to update to the latest version.
Azərbaycanca: Zohocorp ManageEngine M365 Manager Plus və M365 Security Plus proqramlarının 4820 versiyasından aşağı olan versiyaları Exchange Online ehtiyat nüsxə modulunda autentifikasiya olunmuş Path Traversal zəifliyindən təsirlənir. İstismar nəticəsində təsdiqlənmiş zərərli istifadəçi serverdə məhdud əməliyyatlar apara bilər. Mütəxəssislər proqramı ən son versiyaya yeniləməyi tövsiyə edir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which ManageEngine products are affected by CVE-2026-16053?
The CVE-2026-16053 vulnerability affects Zohocorp's ManageEngine M365 Manager Plus and M365 Security Plus.
Does CVE-2026-16053 require authentication to exploit?
Yes, CVE-2026-16053 is an authenticated Path Traversal vulnerability, meaning the malicious user must have a verified account on the system to exploit it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.