Vulnerability Management, Cloud Security

Total system compromise possible with new Microsoft Exchange flaw

(Adobe Stock)

Organizations have been warned by the Cybersecurity and Infrastructure Security Agency and Microsoft regarding the high-severity Microsoft Exchange vulnerability, tracked as CVE-2025-53786, which could allow attackers to transition from on-premises to cloud iterations of the software to facilitate complete system compromise, reports Cybersecurity Dive.

Vulnerable hybrid-joined configurations could be abused by threat actors for privilege escalation, according to a CISA alert, which urged the immediate application of Microsoft's April 2025 Exchange Service hotfixes and the deactivation of internet connectivity for end-of-life Exchange Server and SharePoint Server instances despite the lack of evidence suggesting active exploitation. Meanwhile, Microsoft has called on organizations to use its new Exchange Hybrid app that enables improved management of cloud and on-premises instances as it mulls to prohibit Exchange Web Services traffic in the shared service principal for the time being. "All organizations are strongly encouraged to implement Microsoft guidance to reduce risk," said Acting CISA Executive Assistant Director for Cybersecurity Chris Butera.

An In-Depth Guide to Cloud Security

Get essential knowledge and practical strategies to fortify your cloud security.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds