ED 25-02, Mitigate Microsoft Exchange Vulnerability
In effectCISA · Emergency Directive · August 7, 2025
Summary
Required agencies with hybrid Microsoft Exchange setups to run Microsoft's health checker, disconnect unsupported Exchange servers, and apply Microsoft's April 2025 fix and configuration steps by August 11, 2025, closing a flaw that let attackers move into connected cloud mail.
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- Emergency Directive
- Number
- ED 25-02
- Issued
- August 7, 2025
- Status
- In effect
Still in force, possibly with amendments.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.