28,000+ Microsoft Exchange Servers Vulnerable to CVE-2025-53786 Exposed Online
ID: cb563d2a-2dda-5865-b4ad-7dc0bedc0ce8
STIX ID: report--cb563d2a-2dda-5865-b4ad-7dc0bedc0ce8
Feed Name: cybersecurityNews.com
**Executive summary:** New scanning data shows over 28,000 publicly exposed Microsoft Exchange servers vulnerable to CVE-2025-53786 — a high-severity (CVSS 8.0) hybrid configuration flaw that allows on‑prem Exchange administrators to escalate privileges into Microsoft 365; CISA issued an Emergency Directive requiring fixes, Microsoft published hotfix guidance and plans to block shared-service-principal traffic after October 31, 2025, and researchers demonstrated the exploit at Black Hat USA 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
