logo

28,000+ Microsoft Exchange Servers Vulnerable to CVE-2025-53786 Exposed Online

ID: cb563d2a-2dda-5865-b4ad-7dc0bedc0ce8

STIX ID: report--cb563d2a-2dda-5865-b4ad-7dc0bedc0ce8

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-08-09

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Executive summary:** New scanning data shows over 28,000 publicly exposed Microsoft Exchange servers vulnerable to CVE-2025-53786 — a high-severity (CVSS 8.0) hybrid configuration flaw that allows on‑prem Exchange administrators to escalate privileges into Microsoft 365; CISA issued an Emergency Directive requiring fixes, Microsoft published hotfix guidance and plans to block shared-service-principal traffic after October 31, 2025, and researchers demonstrated the exploit at Black Hat USA 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.