BlueOnyx
ExchangeEmail InfrastructureIT ManagementMigrationCybersecurityEnterprise IT

After October, Your Exchange Servers Will Have No Safety Net

Théodore BaillyPublished on 23 juillet 20265 min read
Cadenas posé sur un clavier, symbole de sécurité informatique

Introduction

Microsoft has made its position final: the Extended Security Updates (ESU) program for Exchange Server 2016 and 2019 ends in October 2026, with no possibility of extension. The company confirmed this publicly on July 22, 2026 — there will be no third coverage period. After that date, no security patches will be issued for these versions, even in the event of a critical vulnerability being actively exploited in the wild.

This isn't entirely a surprise. Both versions had already lost mainstream support — Exchange 2016 in October 2025, Exchange 2019 a few months prior — and the ESU program had provided two successive extension windows. The second closes with no fallback. Organizations that have not yet started their migration now have only weeks left to act.

A High-Value Target in Today's Threat Landscape

Exchange Server holds a unique position in enterprise cyber risk. Mail servers concentrate extraordinary volumes of sensitive business data — contract correspondence, access to corporate calendars and directories, connections to internal systems — while remaining internet-facing by design. They have historically ranked among the most actively targeted assets by sophisticated threat actors, from industrial espionage campaigns and persistent intrusions to ransomware groups using them as an initial foothold into corporate networks.

The end of the ESU program means that any vulnerability discovered in Exchange 2016 or 2019 after October will remain open, with no prospect of an official fix. Organizations keeping these versions in production would be carrying a structural risk that is increasingly indefensible — to their security teams, their cyber insurers, and their regulatory obligations under frameworks such as NIS2 or DORA, depending on the sector.

Two Exit Paths, Each With Its Own Constraints

Microsoft offers two official alternatives.

Exchange Server Subscription Edition (SE) is the route for organizations that want to maintain an on-premises messaging infrastructure. It represents a meaningful model shift: Exchange SE operates on an annual subscription basis, moving away from the perpetual licensing of previous versions. Technically, migration from Exchange 2019 can be performed in-place, without a full environment rebuild. From Exchange 2016, an intermediate step through cumulative update CU23 is required before transitioning to SE. Both legacy versions can temporarily coexist with Exchange SE, enabling a phased mailbox migration — but that coexistence window is time-limited by successive SE updates.

Exchange Online, as part of Microsoft 365, is the alternative for organizations looking to exit on-premises mail infrastructure management entirely. This path involves distinct architectural decisions — identity governance, data compliance policy, potential hybrid scenario management — and requires serious preparation rather than a last-minute scramble.

The Timeline Is Fixed

Whichever path is chosen, the window for action is narrow. By October, IT teams must have formalized their choice, prepared the target environment, and started mailbox migrations. In complex Exchange environments — custom connectors, third-party application integrations, multi-site architectures — that timeline is already tight.

IT leadership that has not yet launched a migration project needs to do so immediately. Running enterprise mail servers without security patches, in a context where these assets are prime targets, is neither a technically defensible posture nor an acceptable decision under today's IT governance standards.

Share

After October, Your Exchange Servers Will Have No Safety Net