HomeIntelligenceBrief
BREACH BRIEF🟠 High Advisory

Microsoft Ends Extended Security Updates for Exchange 2016/2019 in October 2026

Microsoft will stop providing security updates for Exchange Server 2016 and 2019 after October 2026, leaving on‑prem deployments without patches. Organizations must treat this as a control gap in SOC 2 audits and map upgrade actions to evidence of compliance.

LiveThreat™ Intelligence · 📅 July 22, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
AD
Type
Advisory
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
1 recommended
📰
Source
bleepingcomputer.com

Microsoft Ends Extended Security Updates for Exchange 2016/2019 in October 2026

What Happened — Microsoft announced that the Extended Security Update (ESU) program for Exchange Server 2016 and 2019 will cease in October 2026. No further security patches will be released for these products after that date, even for customers currently covered by Period 2 ESU.

Why It Matters for Compliance & Audit Readiness

  • Unpatched legacy Exchange servers become a control gap under SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management).
  • Continuous‑compliance programs must capture upgrade decisions and evidence of patch‑management remediation to satisfy audit reviewers.
  • Mapping this lifecycle risk to a formal control (e.g., “Maintain supported software versions”) provides defensible evidence for SOC 2 readiness.

Who Is Affected — Enterprises across all verticals that still run on‑prem Exchange 2016 or 2019, including financial services, healthcare, government, and education.

Recommended Actions

  • Inventory all Exchange instances and verify ESU expiration dates.
  • Align the upgrade/migration plan with your SOC 2 control mapping and record the decision in your GRC tool.
  • Capture migration evidence (project charter, test results, change‑control tickets) as audit‑ready artifacts.

Technical Notes – The ESU termination does not introduce a new vulnerability, but any unpatched server will be exposed to existing and future Exchange‑related CVEs (e.g., CVE‑2025‑XXXXX). Microsoft recommends moving to Exchange Server Subscription Edition or Exchange Online. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-2016-and-2019-esu-program-ends-in-october/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →