More than 511,000 internet-exposed Microsoft IIS servers that have reached end-of-life are still accessible online, according to Shadowserver scan data cited by multiple reports. Of those, more than 227,000 have also moved beyond Microsoft’s Extended Security Updates window, leaving them fully out of support and ineligible for future critical patches. The largest concentrations of these obsolete IIS systems were identified in China and the United States, with Canada, France, Germany, Italy, the UK, Taiwan, South Korea, and Hong Kong each also reporting more than 10,000 exposed end-of-life servers.
Researchers warned that attackers routinely scan for unpatched edge infrastructure and web servers to exploit known vulnerabilities, gain initial access, and potentially support ransomware or APT operations. Shadowserver has begun labeling affected assets as eol-iis and eos-iis in its daily Vulnerable HTTP reports to help defenders find exposed systems. Recommended actions include auditing internet-facing assets, reviewing Shadowserver exposure data, upgrading or replacing legacy IIS and underlying Windows Server deployments, using ESU where still available, and isolating unavoidable legacy systems behind web application firewalls with tightly restricted access.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
Following the findings, Shadowserver began labeling affected systems as "eol-iis" and "eos-iis" in its daily Vulnerable HTTP reports to help defenders identify exposed legacy IIS assets. The reporting highlighted especially high concentrations in China and the United States.
Shadowserver reported that its daily network scans on 2026-03-23 identified more than 511,000 internet-exposed Microsoft IIS instances that had reached end-of-life. Of these, more than 227,000 had also passed Microsoft's Extended Security Updates period, leaving them fully out of support.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.