Direct Inward Dialing: +1 408 916 9890
| Vulnerability details | |
| Severity | High |
| CVE ID | CVE-2026-16053 |
| Product details | |||
| Name | Affected version(s) | Fixed version(s) | Fixed on |
| M365 Manager Plus | 4818 and earlier | 4820 | 13 July, 2026 |
| M365 Security Plus | 4818 and earlier | 4820 | 13 July, 2026 |
CVE-2026-16053 refers to an authenticated path traversal vulnerability in the Exchange Online backup module that could let an attacker delete arbitrary files on the server.
An authenticated attacker could exploit this vulnerability to delete arbitrary files on the server resulting in a loss of data integrity and availability of services.
The issue has been resolved by implementing path validation to ensure that only valid file and folder paths are processed, preventing path traversal and arbitrary file deletion.
Download and apply the latest service pack from the following links:
This issue was reported by Zewei Zhang from NSFOCUS TIANJI Lab through the Zoho BugBounty program.
Please contact product support at the mail addresses mentioned below for further assistance. You can also contact our security team.