CVE-2026-16053: Zohocorp ManageEngine m365 Manager Plus

High severity, CVSS 8.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.

Affected products

  • Zohocorp ManageEngine m365 Manager Plus: before 4820 (fixed in 4820)
  • Zohocorp ManageEngine m365 Security Plus: before 4820 (fixed in 4820)

Published 2026-08-11. Last modified 2026-08-31.