AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16053

HIGH · CVSS 8.5 EPSS 0.99%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability affects Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions prior to 4820, specifically within the Exchange Online backup module, allowing authenticated users to exploit a path traversal flaw. This could lead to unauthorized access to sensitive files and data, posing a significant risk to the security of the affected systems. Organizations using these ManageEngine products should prioritize patching to mitigate potential data breaches and unauthorized access.

CVE
CVE-2026-16053
Severity
HIGH
CVSS
8.5
EPSS
0.99%
Exchange

Original NVD Description

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.