:

MICROSOFT ENDS EXCHANGE 2016/2019 SUPPORT

SECURITY DESK1 MIN READ
WED, JUL 22, 2026

■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE

Microsoft will discontinue security updates for Exchange 2016 and 2019 in October through its Extended Security Update program. Organizations running these versions must migrate to supported platforms.

Microsoft is phasing out security patches for Exchange 2016 and 2019, marking the end of the Extended Security Update (ESU) program for these versions. The deadline falls in October. Customers still relying on these older Exchange versions face increased security risks after the cutoff date. Microsoft recommends migrating to Exchange 2021 on-premises or Exchange Online in Microsoft 365. Exchange 2016 reached mainstream support end in October 2020, while Exchange 2019 reached mainstream support end in October 2023. The ESU program provided additional security updates beyond mainstream support periods. Organizations delaying migration should prioritize planning their upgrade path. Staying on unsupported versions exposes systems to unpatched vulnerabilities that attackers can exploit. Microsoft has provided extended timelines for customers to transition, with resources available on its support pages for migration planning.

■ SOURCES

Bleeping ComputerArs Technica

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Security researchers discovered that LG smart TVs continue recording audio and scanning local networks even when the display is powered down. The findings raise concerns about user privacy and device security.

1H AGOIndustry Desk

ConnectWise has disclosed a new vulnerability in ScreenConnect remote access software without an immediate patch available. The company is offering temporary mitigation measures while preparing a fix for later this week.

1H AGOIndustry Desk

Hackers are actively exploiting a chain of two newly disclosed vulnerabilities in MikroTik RouterOS to seize control of routers with exposed SSH services. The attacks target internet-facing devices and pose immediate risk to affected networks.

1H AGOSecurity Desk

N-able has released an emergency hotfix for a maximum-severity remote code execution vulnerability in its N-central RMM platform. The flaw is being actively exploited in ongoing attacks.

5H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.