CVE-2025-53786 is a high-severity vulnerability affecting Microsoft Exchange Server, stemming from security implications tied to configuration steps outlined in an April 2025 announcement for hybrid deployments. With a CVSS score of 8.0, it presents a high risk of compromise (C:H, I:H, A:H) through a network attack vector (AV:N) with high privileges required (PR:H) and high attack complexity (AC:H). While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating high awareness. Microsoft strongly recommends installing the April 2025 (or later) hotfix and implementing the documented changes to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2016:cumulative_update_23:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_14:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2019:cumulative_update_15:*:*:*:*:*:* | ||
< 15.02.2562.017CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server_subscription_edition:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.