Microsoft has warned its customers to mitigate a high-severity vulnerability in hybrid Exchange Server deployments that could allow attackers to escalate privileges in Exchange Online environments (part of Microsoft 365) without leaving a trace.
See also: NightEagle group targets China via Microsoft Exchange

Exchange hybrid setups connect on-premises Exchange servers with Exchange Online, enabling seamless integration of email and calendar features between on-premises and cloud mailboxes, including shared calendars, global address lists, and email flow.
However, in hybrid Exchange deployments, the on-premises Exchange server and Exchange Online share the same service principal, which is a common identity used for authentication between the two environments. By exploiting this common identity, attackers controlling on-premises Exchange can potentially forge or manipulate trusted tokens or API calls that the cloud side will accept as legitimate, as it automatically trusts the on-premises server.
Additionally, actions originating from on-premises Exchange do not always produce logs related to malicious behavior in Microsoft 365. Therefore, traditional breach detection may not capture security breaches if they originated from on-premises environments.
"In a hybrid Exchange deployment, an attacker who first gains administrative access to an on-premises Exchange server could potentially escalate their privileges within the organization's connected cloud environment without leaving an easily detectable and auditable trail," Microsoft said in a security advisory describing a high-severity privilege escalation vulnerability now being tracked as CVE-2025-53786.
The vulnerability affects Exchange Server 2016 and Exchange Server 2019, as well as Microsoft Exchange Server Subscription Edition, the latest version, which replaces the traditional perpetual license model with a subscription-based model.
See also: Microsoft Exchange Online marks Gmail emails as spam
While Microsoft has not yet observed a real-world exploit, the company has labeled it as "Most Likely Exploitable" because its analysis revealed that exploit code could be developed to exploit this vulnerability consistently, increasing its attractiveness to attackers.

CISA issued a separate advisory addressing this issue and advised network defenders who want to secure their hybrid Exchange deployments against potential attacks targeting the CVE-2025-53786 to install Microsoft's Exchange Server Hotfix updates from April 2025 on the on-premises Exchange server and follow Microsoft's configuration guidelines.
For organizations using hybrid Exchange or those who have previously configured hybrid Exchange but are no longer using it, CISA advised reviewing Microsoft's Service Principal Cleanup Operation for guidance on resetting keyCredentials . Once complete, organizations should run the Microsoft Exchange Health Checker to determine if further steps are required.
CISA warned that failure to mitigate this vulnerability could lead to a total compromise of the hybrid cloud and on-premises environment, and urged administrators to disconnect public servers running Exchange Server or SharePoint Server versions that have reached end-of-life or end-of-service from the internet.
In January, Microsoft reminded administrators that Exchange 2016 and Exchange 2019 will reach the end of extended support in October and shared guidance for those who need to retire old servers, advising them to migrate to Exchange Online or upgrade to Exchange Server Subscription Edition.
See also: CISA – Issues Best Practices for Securing Microsoft 365 Cloud Environments
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
In recent years, financially motivated or state-backed attackers have exploited several Exchange security vulnerabilities, including the zero-day ProxyLogon and ProxyShell , to compromise servers. For example, at least ten hacker groups exploited ProxyLogon in March 2021, including a Chinese-backed threat tracked as Hafnium .
