Microsoft encourages users to be on duty after fault in high difficulty in hybrid exchange installations


  • Microsoft finds faults with high severity in hybrid swap sponsors
  • Both Exchange Server 2016 and Exchange Server 2019 are touched, and so is Microsoft Exchange Server -Subscription Edition
  • A hotfix is available so users need to update now

Microsoft has called on its customers to be in high alarm after discovering a dangerous vulnerability in hybrid exchange installations.

Microsoft describes the problem as a “incorrect approval” error traced as CVE-2025-53786 with a severity of 8.0/10 (high). Threat actors with administrator access to an On-Prem Exchange server can use the vulnerability to escalate privileges to the connected Exchange Online environment due to trust errors in shared service head configurations.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top