Microsoft Warns of Probable Exchange Hybrid Flaw Allowing Attackers to Access Microsoft 365 Undetected


Microsoft is investigating a major security risk in Exchange Server hybrid deployments that could let attackers gain escalated access within connected Microsoft 365 cloud environments. The vulnerability, CVE-2025-53786, affects Exchange Server 2016, Exchange Server 2019, and the Subscription Edition.

If an attacker gets admin control over the on-premises Exchange server, they can forge authentication tokens or make API calls that the cloud side accepts as valid. Because Exchange Online trusts the on-premises server by default, these actions can go unnoticed, as they often avoid detection in standard Microsoft 365 audit tools, as reported by Bleeping Computer.

Microsoft says the issue could lead to a full compromise of both the cloud and on-premises environments. Although there are no known attacks yet, Microsoft has marked the issue as “Exploitation More Likely,” meaning that creating working exploit code would not be difficult and could appeal to threat actors. CISA also published advice with a warning that ignoring this vulnerability may result in complete security failure across affected systems.

Microsoft is urging admins to install the hotfixes released in April 2025 and switch to a dedicated Exchange hybrid application in Entra ID. Organizations no longer using hybrid setups should follow the documentation to reset shared identity credentials. Microsoft also recommends running the Exchange Server Health Checker and disconnecting unsupported Exchange and SharePoint servers from the internet.

Leave a Reply

Your email address will not be published. Required fields are marked *