editor speak logo
  • Business Tech
  • Startups & VC
  • Business Insights
  • Finance & Markets
  • FutureTech
  • Enterprise & SaaS

Enterprise & SaaS

Urgent Alert: CISA and Microsoft Warn Vulnerability in Hybrid Exchange Servers

Munish Gupta Munish Gupta
|
Published on November 6, 2025

Late Wednesday, Microsoft and the Cybersecurity and Infrastructure Security Agency (CISA) cautioned about a recently found vulnerability in hybrid Microsoft Exchange. This defect could allow attackers to move from the on-premises edition of the program to its cloud equivalent, so maybe seize whole system control.

Identified as CVE-2025-53786, this vulnerability could enable an attacker with administrative access to the on-premises Exchange to increase their privileges by exploiting weak hybrid-joined configurations, according to CISA’s alert.

Cybersecurity and Infrastructure Security Agency (CISA)

Microsoft has not yet seen any indications that hackers are actively exploiting this vulnerability, according to the CISA alert. Preferring to remain anonymous to offer an honest assessment, a CISA employee confirmed that the agency has similarly not seen any evidence of exploitation.

Microsoft released the April 2025 Exchange Server hotfix updates, which CISA has urged users running on-premises Exchange servers to download immediately. The agency also advised businesses to remove any internet-connected copies of SharePoint Server and Microsoft Exchange Server that have reached their end-of-life date.

Also read: Windows 11 Widgets Get an AI Overhaul with Copilot Discover

Microsoft revealed plans to temporarily restrict Exchange Web Services traffic via the company’s shared service principal in response to this. Furthermore, the company has urged its clients to switch to the Exchange Hybrid app, which Microsoft characterizes as a rich coexistence between its cloud and on-premises products. Users may therefore use other connected tools, check calendar status, and post profile images. Earlier in April, Microsoft advised consumers of the need for this migration. That change process is anticipated to be sped up by the Wednesday declaration.

“All companies are strongly urged to follow Microsoft instructions to lower risk,” said Chris Butera, the acting executive assistant director for cybersecurity for CISA. He cited the cooperation between Microsoft and CISA in addressing this vulnerability as another example of the kind of operational partnership that is securing the essential infrastructure of the country. 

RECENT POSTS
Gold Prices Up as Traders Weigh Jobs Data and Shutdown…
November 14, 2025
Cloud AI Update: Microsoft Leads Cloud Computing Market Boom Toward…
November 14, 2025
$1 Trillion AI Market: AMD Targets Massive Chip Growth Plan
November 14, 2025
SoftBank Sells All Nvidia Stake Worth $5.83B to Boost AI…
November 14, 2025
PhysicsWallah’s ₹3,480-Cr IPO Opens Today After Anchor Book Nabs ₹1,563…
November 13, 2025
CATEGORIES
    • Business Insights
    • Business Tech
    • BusinessToday
    • Enterprise & SaaS
    • Finance & Markets
    • FutureTech
    • Startups & VC
  • Related Posts
    Pine Labs Ipo boost
    Pine Labs Allots Shares Worth ₹1,754 Crore to Anchor Investors…
    Pine Labs has raised ₹1,754 crore from anchor investors ahead of its... Swaraj
    nvidia and qualcomm
    NVIDIA and Qualcomm Power $1.8B Boost for India’s Deep Tech…
    Nvidia and Qualcomm have joined the India Deep Tech Alliance to boost... Swaraj
    urban company q2 fy26 37 percent revenue growth
    Urban Company’s Core Business Remains Profitable Amidst 37% Revenue Surge
    Urban Company reported a 37% year-on-year revenue surge to ₹380 crore in... Swaraj
    stampmyvisa raises 4cr ai visa
    StampMyVisa Secures ₹4 Cr to Scale AI Visa Tech and…
    Led by current supporter Unicorn India Ventures, StampMyVisa has reported the successful... Swaraj
    editor speak logo

    We deliver fast, accurate news and in-depth analysis, keeping readers updated with unbiased reports across politics, business, sports, and entertainment.

    News Categories
    • FutureTech
    • Business Insights
    • Finance & Markets
    • Business Tech
    • Business Today
    • Enterprise & SaaS
    • Startups & VC
  • Important Links
    • About Us
    • Privacy Policy
    • Correction Policy
    • Fact Checking Policy
    • Disclaimer
  • CONTACT
    • info@editorspeak.com

    Copyright © 2025 editorspeak.com