{"id":51741,"date":"2025-08-07T09:53:08","date_gmt":"2025-08-07T09:53:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/51741\/"},"modified":"2025-08-07T09:53:08","modified_gmt":"2025-08-07T09:53:08","slug":"cisa-issues-urgent-microsoft-cve-2025-53786-security-warning","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/51741\/","title":{"rendered":"CISA Issues Urgent Microsoft CVE-2025-53786 Security Warning"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/ca\/wp-content\/uploads\/2025\/08\/1754560388_711_960x0.jpg\" alt=\"Microsoft Office Building in New York City\" data-height=\"1983\" data-width=\"3186\" style=\"position:absolute;top:0\"\/><\/p>\n<p>CISA issues Microsoft Exchange Server CVE-2025-53786 warning<\/p>\n<p>Getty Images<\/p>\n<p>Hot on the heels of an official security advisory from <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/02\/24\/us-government-supercharges-security-vulnerabilities\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/02\/24\/us-government-supercharges-security-vulnerabilities\/\" target=\"_self\" aria-label=\"America\u2019s Cyber Defense Agency\" rel=\"nofollow noopener\">America\u2019s Cyber Defense Agency<\/a> warning of <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/06\/camera-hacks-ongoing---americas-cyber-defense-agency-confirms\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/06\/camera-hacks-ongoing---americas-cyber-defense-agency-confirms\/\" target=\"_self\" aria-label=\"camera hack attacks\" rel=\"nofollow noopener\">camera hack attacks<\/a>, the U.S. Cybersecurity and Infrastructure Security Agency has issued another alert. This time, it impacts users of Microsoft Exchange Server and, without immediate remediation, could enable an attacker to escalate privileges and \u201cimpact the identity integrity of an organization\u2019s Exchange Online service.\u201d Here\u2019s what you need to know.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-1\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/07\/google-confirms-it-has-been-hacked---user-data-stolen\/\" target=\"_blank\" aria-label=\"Google Confirms It Has Been Hacked \u2014 User Data Stolen\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/07\/google-confirms-it-has-been-hacked---user-data-stolen\/\" rel=\"nofollow noopener\">ForbesGoogle Confirms It Has Been Hacked \u2014 User Data StolenBy Davey Winder<\/a><br \/>\nCISA And Microsoft Warn Users Of CVE-2025-53786 Attack Danger<\/p>\n<p>There have been a number of security warnings impacting Microsoft users of late that may have caught your attention: the <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/04\/microsoft-windows-is-being-hacked-if-you-see-these-jpeg-images\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/04\/microsoft-windows-is-being-hacked-if-you-see-these-jpeg-images\/\" target=\"_self\" aria-label=\"Windows JPEG hackers\" rel=\"nofollow noopener\">Windows JPEG hackers<\/a> and, of course, the by now infamous <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/21\/microsoft-confirms-ongoing-mass-sharepoint-attack---no-patch-available\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/21\/microsoft-confirms-ongoing-mass-sharepoint-attack---no-patch-available\/\" target=\"_self\" aria-label=\"SharePoint Server attacks\" rel=\"nofollow noopener\">SharePoint Server attacks<\/a> to name but two. The very latest, however, comes with the added weight of a CISA alert attached.<\/p>\n<p>\u201cCISA is aware of the newly disclosed high-severity vulnerability, CVE-2025-53786,\u201d the <a class=\"color-link\" href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/08\/06\/microsoft-releases-guidance-high-severity-vulnerability-cve-2025-53786-hybrid-exchange-deployments\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/08\/06\/microsoft-releases-guidance-high-severity-vulnerability-cve-2025-53786-hybrid-exchange-deployments\" aria-label=\"August 6 advisory\">August 6 advisory<\/a> warned, \u201cthat allows a cyber threat actor with administrative access to an on-premise Microsoft Exchange server to escalate privileges by exploiting vulnerable hybrid-joined configurations.\u201d<\/p>\n<p>Microsoft, meanwhile, has <a class=\"color-link\" href=\"https:\/\/techcommunity.microsoft.com\/blog\/exchange\/dedicated-hybrid-app-temporary-enforcements-new-hcw-and-possible-hybrid-function\/4440682\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/techcommunity.microsoft.com\/blog\/exchange\/dedicated-hybrid-app-temporary-enforcements-new-hcw-and-possible-hybrid-function\/4440682\" aria-label=\"said\">said<\/a> that \u201cstarting in August 2025, we will begin temporarily blocking Exchange Web Services traffic using the Exchange Online shared service principal,\u201d as part of a \u201cphased strategy to speed up customer adoption of the dedicated Exchange hybrid app and making our customers\u2019 environments more secure.\u201d<\/p>\n<p>CISA added that it \u201chighly recommends entities disconnect public-facing versions of Exchange Server or SharePoint Server that have reached their end-of-life (EOL) or end-of-service from the internet.\u201d<\/p>\n<p>Although CISA confirmed that there has not been any observed active exploitation of CVE-2025-53786, it strongly urged organizations to follow the Microsoft guidance on this issue.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-2\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/05\/google-confirms-accounts-are-being-hacked---how-to-recover-yours\/\" target=\"_blank\" aria-label=\"Google Confirms Accounts Are Being Hacked \u2014 How To Recover Yours\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/05\/google-confirms-accounts-are-being-hacked---how-to-recover-yours\/\" rel=\"nofollow noopener\">ForbesGoogle Confirms Accounts Are Being Hacked \u2014 How To Recover YoursBy Davey Winder<\/a><\/p>\n<p><a class=\"color-link\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-53786\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cve.org\/CVERecord?id=CVE-2025-53786\" aria-label=\"CVE-2025-53786\">CVE-2025-53786<\/a> is officially listed as a Microsoft Exchange Server Hybrid Deployment elevation of privilege vulnerability that follows an accompanying non-security hot fix when the hybrid deployments were announced on April 18. \u201cFollowing further investigation,\u201d the official Common Vulnerabilities and Exposures database entry reads, \u201cMicrosoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"CISA issues Microsoft Exchange Server CVE-2025-53786 warning Getty Images Hot on the heels of an official security advisory&hellip;\n","protected":false},"author":2,"featured_media":51742,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[49,48,17436,17437,35214,35218,35215,35216,35217,61],"class_list":["post-51741","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-ca","tag-canada","tag-cisa","tag-cisa-warning","tag-cve-2025-53786","tag-microsoft-exchange","tag-microsoft-exchange-server","tag-microsoft-security-warning","tag-microsoft-server","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/51741","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=51741"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/51741\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/51742"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=51741"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=51741"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=51741"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}