Microsoft said the Extended Security Update (ESU) program for Exchange Server 2016 and Exchange Server 2019 will end in October 2026 with no further extension. The notice follows Microsoft's April announcement of a second ESU period, a six-month continuation after both on-premises Exchange versions had already reached end of support, confirming that customers relying on legacy deployments now face a fixed deadline for receiving security patches.
Microsoft is urging organizations to move to Exchange Server Subscription Edition (SE) or migrate to Exchange Online as support winds down. The company’s lifecycle guidance and follow-up reporting indicate that Exchange 2019 customers can perform an in-place upgrade to Exchange Server SE in a process similar to installing a cumulative update, while Exchange 2016 customers must plan a broader migration path before security coverage ends.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Microsoft said there will be no further extension of the Extended Security Update program for Exchange Server 2016 and 2019 beyond October 2026. The company urged administrators to upgrade to Exchange Server Subscription Edition or migrate to Exchange Online or Microsoft 365.
Microsoft announced in April 2026 a six-month extension creating Period 2 of the Extended Security Update program for Exchange Server 2016 and 2019 after both products had reached end of support.
Microsoft Exchange Server 2019 reached end of support, prompting customers to rely on Extended Security Updates or migrate to newer offerings.
Microsoft Exchange Server 2016 reached end of support, after which it no longer received standard support or security updates outside the ESU program.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcetechcommunity.microsoft.com
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.