CISA | Alerts
Follow
Microsoft Releases Guidance on High-Severity Vulnerability (CVE-2025-53786) in Hybrid Exchange Deployments
CISA is alerting organizations to a critical vulnerability, CVE-2025-53786, affecting Microsoft Exchange servers. This vulnerability allows attackers with administrative access to escalate privileges in hybrid-joined configurations. Successful exploitation could compromise an organization's Exchange Online service identity integrity. Although no exploitation has been observed, CISA strongly advises immediate action to prevent a total domain compromise. Organizations using Exchange hybrid must review Microsoft's guidance on security changes for hybrid deployments. Implementing Microsoft's April 2025 Exchange Server Hotfix Updates on on-premise servers is crucial. Follow Microsoft's instructions for deploying a dedicated Exchange hybrid app. For existing or past hybrid configurations, reset service principal keyCredentials using Service Principal Clean-Up Mode guidance. After these steps, run the Microsoft Exchange Health Checker to verify. CISA also recommends disconnecting end-of-life Exchange and SharePoint servers from the internet. Organizations should monitor Microsoft's dedicated hybrid app blog for further updates.