Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-16053 is an authenticated path traversal vulnerability affecting Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820. This vulnerability exists in the Exchange Online backup module and allows an authenticated attacker to traverse the file system and access unauthorized files. Organizations relying on ManageEngine for Microsoft 365 backup and security management are directly impacted, particularly those who have not patched to version 4820 or later. Path traversal vulnerabilities are particularly dangerous in backup systems because they can expose sensitive configuration files, credentials, and backup data that contain critical organizational information.
While this CVE does not currently map to specific MITRE ATT&CK techniques, Casky's Claude AI-powered analysis can detect path traversal attack patterns through behavioral anomalies in file access requests and directory enumeration attempts. Although Casky currently has zero matching skills indexed for this specific vulnerability, practitioners using the platform would benefit from monitoring for reconnaissance activity (ATT&CK T1087, T1580) where attackers probe directory structures, and credential access patterns (ATT&CK T1110) if exposed credentials are discovered through traversal. Extended reasoning capabilities would identify suspicious sequences of authenticated requests attempting to access files outside the intended backup directory, flagging deviations from normal ManageEngine operational patterns and alerting teams to potential exploitation before data exfiltration occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-16053. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation