Microsoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October.
This comes after a 6-month extension announced in April 2026 to the original ESU program, which began in October after Exchange Server 2016 and 2019 reached the end of support.
Exchange 2016 reached mainstream support in October 2020, while Exchange 2019 mainstream support ended in January 2024.
“Over the last several weeks we have received several questions about possible extension of the Exchange Server 2016/2019 ESU program past October 2026,” the Exchange Server team said in a Monday blog post.
“After all, in our original Exchange 2016/2019 ESU announcement we said that there would be no extensions, but then we ended up creating a Period 2 Exchange ESU program that is scheduled to end with October 2026. We are just about at the mid-point of Period 2 Exchange ESU now.
“There will be no further extension of Exchange 2016/2019 ESU program timeline. Once October 2026 ends, there will be no further updates for Exchange 2016/2019, even if you currently have a Period 2 ESU.”
Microsoft advised IT admins to upgrade to Exchange Server Subscription Edition (SE), as they can perform in-place upgrades from Exchange Server 2019, a process identical to installing a Cumulative Update (CU).
Admins who still have servers running Exchange 2016 or 2013 in production are also advised to directly upgrade to Exchange Server SE or, first, install Exchange 2019.
Detailed Microsoft 365 migration guidance is available for global admins on Microsoft’s documentation site, which also provides more information on how to migrate to Exchange Online (available as a standalone service or as an Office 365 subscription).
In June, Microsoft quietly extended the free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to continue receiving security updates up until October 2027.
Earlier this month, it also announced that Windows Server 2022 and Windows 11 24H2 Home and Pro editions will reach the end of support in 90 days, but will switch to extended support and continue receiving security updates.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Microsoft patches Exchange Server zero-day exploited in attacks
Microsoft releases Windows 10 KB5099539 extended security update
Microsoft quietly extends free Windows 10 ESU support to October 2027
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Microsoft to retire the OWA Light client in Exchange Server
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
Hugging Face warns an autonomous AI agent hacked its network
Critical ServiceNow code execution flaw now exploited in attacks
Calculate what you’d save by replacing your MDR.
Overdue a password health-check? Audit your Active Directory for free
See how Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Read the case study.
Pentest your web apps on-demand. Find what humans miss. Scope and launch a pentest in minutes.
Privacy by policy or privacy by architecture? See how age checks work when the face never leaves the device.
Do you have what it takes to challenge DARKROOM? Signup for an exclusive DEFCON CTF!
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



