Microsoft issued guidance for CVE-2025-53786, a high-severity vulnerability in hybrid Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition deployments that can let an attacker with administrative access to an on-premises Exchange server escalate privileges into the connected cloud tenant. The issue stems from hybrid environments using a shared service principal tied to the Exchange Online application, creating a trust path that could enable unauthorized access to cloud data and services; Microsoft said it had not observed active exploitation but warned abuse would be difficult to detect.
The company has been moving customers away from that shared identity model under its Secure Future Initiative, releasing April 2025 Hotfix Updates to support migration to a dedicated Exchange hybrid application in Microsoft Entra ID. Organizations that rely on hybrid "rich coexistence" features such as Free/Busy, MailTips, and profile photo sharing must complete the dedicated-app migration before October 2025, when Exchange Online will stop allowing the shared service principal approach, and later transition hybrid calls from EWS to Microsoft Graph permissions before October 2026 as Exchange Online retires legacy EWS-based integration.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that Microsoft had issued mitigation guidance for CVE-2025-53786, a high-severity flaw affecting hybrid Exchange deployments that could let an attacker with on-premises administrative access escalate privileges into the connected cloud environment. The report also said Microsoft had not detected active exploitation at that time and noted the shared service principal model would be disabled on 2025-10-31.
Microsoft announced security-driven changes for Exchange hybrid deployments, including moving tenants from the shared Exchange Online service principal to a dedicated Exchange hybrid application in Entra ID. The change was described as starting with the April 2025 Hotfix Update as part of Microsoft's Secure Future Initiative.
Microsoft released April 2025 Hotfix Updates for Exchange Server 2016 and 2019. The updates added functionality and fixes, and Microsoft stated they did not include any new Exchange Server security updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcetechcommunity.microsoft.com
Open sourcetechcommunity.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.