Microsoft Discloses Exchange Server Flaw Enabling Silent Cloud Access in Hybrid Setups
On-premise versions of Exchange Server have a high-severity security issue that, in some circumstances, might grant an attacker enhanced access, according to a Microsoft alert.
The vulnerability has a CVSS score of 8.0 and is identified as CVE-2025-53786. The flaw was reported by Outsider Security's Dirk-jan Mollema, who has been credited.
According to the tech giant's notice, in an Exchange hybrid implementation, an attacker who initially obtains administrator access to an on-premises Exchange server may be able to escalate privileges across the company's connected cloud environment without leaving readily identifiable and auditable traces.
In hybrid settings, Exchange Server and Exchange Online use the same service principle, which creates this danger.
According to the corpo...

