Skip to content

ED 25-02, Mitigate Microsoft Exchange Vulnerability

In effectCISA · Emergency Directive · August 7, 2025

Summary

Required agencies with hybrid Microsoft Exchange setups to run Microsoft's health checker, disconnect unsupported Exchange servers, and apply Microsoft's April 2025 fix and configuration steps by August 11, 2025, closing a flaw that let attackers move into connected cloud mail.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
Emergency Directive
Number
ED 25-02
Issued
August 7, 2025
Status
In effect

Still in force, possibly with amendments.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.