CVE-2026-16053: M365 Manager Plus 和 M365 Security Plus 中的认证路径遍历漏洞 漏洞概述 CVE ID: CVE-2026-16053 严重程度: 高 描述: 该漏洞涉及 Exchange Online 备份模块中的认证路径遍历漏洞,攻击者可以利用此漏洞在服务器上删除任意文件。 影响范围 受影响版本: - M365 Manager Plus: 4818 及更早版本 - M365 Security Plus: 4818 及更早版本 影响: 认证攻击者可以利用此漏洞删除服务器上的任意文件,导致数据完整性和服务可用性损失。 修复方案 修复版本: - M365 Manager Plus: 4820 - M365 Security Plus: 4820 修复日期: 2026年7月13日 具体步骤: 下载并应用最新的服务包,链接如下: - M365 Manager Plus: https://www.manageengine.com/microsoft-365-management-reporting/service-pack.html - M365 Security Plus: https://www.manageengine.com/microsoft-365-security-protection/service-pack.html 致谢 该问题由 Zewei Zhang 从 NSFOCUS TIANJI Lab 通过 Zoho BugBounty 项目报告。 如需进一步帮助,请联系产品支持或安全团队: - M365 Manager Plus 支持: m365managerplus-support@manageengine.com - M365 Security Plus 支持: m365securityplus-support@manageengine.com