Support
 
PhoneGet Quote
 
Support
 
US Sales: +1 888 720 9500
US Support: +1 844 245 1108
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9890

 
 

CVE-2026-16053: Authenticated path traversal vulnerability in M365 Manager Plus and M365 Security Plus

Vulnerability details
Severity High
CVE ID CVE-2026-16053
Product details
Name Affected version(s) Fixed version(s) Fixed on
M365 Manager Plus 4818 and earlier 4820 13 July, 2026
M365 Security Plus 4818 and earlier 4820 13 July, 2026

Details

CVE-2026-16053 refers to an authenticated path traversal vulnerability in the Exchange Online backup module that could let an attacker delete arbitrary files on the server.

Impact

An authenticated attacker could exploit this vulnerability to delete arbitrary files on the server resulting in a loss of data integrity and availability of services.

Fix

The issue has been resolved by implementing path validation to ensure that only valid file and folder paths are processed, preventing path traversal and arbitrary file deletion.

Steps to update

Download and apply the latest service pack from the following links:

Acknowledgements

This issue was reported by Zewei Zhang from NSFOCUS TIANJI Lab through the Zoho BugBounty program.

Please contact product support at the mail addresses mentioned below for further assistance. You can also contact our security team.

A holistic Microsoft 365 administration solution