Microsoft said Extended Security Updates for Exchange Server 2016 and Exchange Server 2019 will end in October 2026, closing the final support path for organizations still running those on-premises versions. The company had already ended mainstream support for both products on October 14, 2025, after which they stopped receiving regular security updates, bug fixes, technical support, and time zone updates; the current Period 2 ESU offering followed a six-month extension and Microsoft said it will not be extended again.
Microsoft is directing affected customers to move to Exchange Server Subscription Edition (SE), now the only supported on-premises Exchange release, or migrate to Exchange Online or Microsoft 365. Organizations running Exchange Server 2019 CU15 can transition to Exchange Server SE through an in-place cumulative update without a new license key, while older deployments require legacy migration, and the guidance applies across on-premises, hybrid, and management-tools-only Exchange environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft reminded customers that Extended Security Updates for Exchange Server 2016 and 2019 will end in October 2026. The company said the current Period 2 ESU program, which followed a six-month extension after end of support, would not be extended again and urged upgrades or migration to Microsoft 365.
Microsoft ended support for Exchange Server 2016 and Exchange Server 2019 on October 14, 2025. After that date, those versions no longer received security updates, bug fixes, technical support, or time zone updates.
Microsoft made Exchange Server Subscription Edition available as the supported on-premises Exchange option. The release gave organizations on Exchange Server 2016 and 2019 a migration target to remain supported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecsirt.sk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.