
A critical zero-day vulnerability in Microsoft Exchange is allowing attackers to pivot from on-premise servers directly into a company’s cloud environment, posing an immediate and severe threat to UK businesses.
Microsoft’s August updates have revealed a major zero-day vulnerability in Microsoft Exchange, posing a high-priority threat to UK organisations.
The critically-rated flaw allows an attacker to pivot from a compromised on-premise Exchange server directly into a company’s cloud environment. This could lead to a compromise of Exchange Online and other connected Office 365 services.
This is a particularly urgent issue for UK firms. Experts have highlighted that the vulnerability can turn a significant on-premise breach into a difficult-to-detect cloud compromise, making it far more dangerous than a simple server flaw.
Reports indicate there are thousands of on-premise Exchange servers publicly facing the internet and vulnerable to this issue.
Many are likely running older, unpatched versions, compounding the risk. Furthermore, the fix for this flaw requires more than just a patch; it involves manual steps to secure the hybrid connection between on-premise and cloud environments, a process many IT teams might overlook.
This vulnerability is a stark reminder that the security of a hybrid environment is only as strong as its weakest link.
UK organisations must treat this new security update as a critical event, taking immediate manual steps to secure their Exchange and cloud services before attackers exploit this new gateway to their data.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543