CISA, in collaboration with the NSA and international partners, has released new security best practices for on-premises Microsoft Exchange servers, emphasizing the urgent need for organizations to harden authentication, enforce strong network encryption, and minimize attack surfaces. The guidance specifically warns against retaining end-of-life Exchange servers in hybrid environments, as these systems remain highly vulnerable to exploitation by malicious actors. Organizations are strongly advised to decommission unsupported Exchange servers after migrating to Microsoft 365 to reduce exposure to ongoing cyber threats.
In Germany, the Federal Office for Information Security (BSI) reported that 92% of public-facing Exchange servers are still running out-of-support software, just weeks after Microsoft ended support for Exchange 2016 and 2019. This widespread use of unsupported versions affects thousands of companies and public sector organizations, including hospitals, schools, and local authorities. The BSI highlighted that if new critical vulnerabilities are discovered, Microsoft will not provide patches, potentially forcing organizations to take servers offline and risking severe operational disruptions, data leaks, and ransomware attacks due to inadequate network segmentation and hardening.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
CISA and NSA, joined by the Australian Cyber Security Centre and the Canadian Centre for Cyber Security, released new best-practices guidance for securing on-premises and hybrid Microsoft Exchange servers. The guidance focused on reducing attack surface, strengthening authentication and admin controls, enforcing encryption, keeping systems updated, and decommissioning end-of-life Exchange servers after migration to Microsoft 365.
Germany's Federal Office for Information Security (BSI) warned that 92% of the country's public-facing Microsoft Exchange servers—about 33,000 systems—were running unsupported software. The agency said the exposure affected critical sectors including hospitals, schools, and government bodies, and urged upgrades, tighter access controls, and network segmentation.
Microsoft ended support for Exchange Server 2016 and 2019 on October 14, leaving those on-premises versions without standard support. The reporting notes Microsoft offered a limited six-month Extended Update Program, after which no further security updates would be available.
Shortly after CISA's emergency directive, Shadowserver reported that more than 29,000 Microsoft Exchange servers remained vulnerable. The finding underscored the scale of internet-exposed risk despite urgent federal mitigation requirements.
CISA issued Emergency Directive 25-02 in August 2025 requiring Federal Civilian Executive Branch agencies to mitigate CVE-2025-53786 within four days. The directive was driven by concerns that exploitation of on-premises Exchange could enable lateral movement into Microsoft cloud environments and potentially total domain compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcecisa.gov
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourcebankinfosecurity.com
Open sourcecyberscoop.com
Open sourcegovinfosecurity.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.