Exchange 2016 and 2019 Security Updates End in October

What happened
Microsoft has confirmed that its Extended Security Update (ESU) program for on-premises Exchange Server 2016 and Exchange Server 2019 will stop shipping patches in October, according to reporting from BleepingComputer. The ESU program was the last stopgap for organizations still running these versions on their own hardware, and once it ends, no further security fixes will be released, regardless of severity.
For anyone still hosting mail on-prem in Pittsburgh and the surrounding region, that's the practical definition of end-of-life. New Exchange vulnerabilities discovered after the cutoff will remain unpatched forever on 2016/2019 boxes. From October 2026 forward, every day you keep those servers reachable from the internet is a day you're accruing risk that no firewall rule or antivirus product can undo.

Why this matters for local SMBs
We still see on-prem Exchange in Pittsburgh more often than you'd think, especially at law firms, CPA practices, specialty medical groups, and small manufacturers that virtualized a 2016 server years ago and never had a reason to touch it again. It works, it's paid for, and email is one of those "if it isn't broken" systems. That calculus changes the moment security updates stop.
A few concrete reasons this hits our client base harder than the average headline suggests:
- Regulated industries can't ignore unpatched systems. If you're subject to HIPAA, the FTC Safeguards Rule, SOC 2, or working toward CMMC Level 2 as a defense subcontractor, running an unsupported mail server that stores CUI, PHI, or client financials is going to fail an audit or an insurance renewal. Cyber liability carriers have been explicit: unsupported software is a coverage problem.
- Exchange has been a top ransomware entry point. The ProxyShell and ProxyNotShell classes of vulnerabilities are still being exploited in the wild against unpatched servers. Attackers scan for these every hour of every day. When patches stop, the exploit window becomes permanent.
- Hybrid Exchange complicates the migration. Many local SMBs are already on Microsoft 365 for mailboxes but kept an on-prem Exchange server around for attribute management. That server still needs to be supported, and Microsoft's newer Exchange Server Subscription Edition (SE) is the intended path forward — but the exact licensing and coexistence details are something you should verify with your licensing partner before you plan the cutover.
- 10–200 employees is the sweet spot for silent risk. You're big enough to be a worthwhile ransomware target and small enough that a compromised mail server can take the whole business offline for a week.
What to do about it this week
You have roughly three months before the ESU tap shuts off. That is enough time to move deliberately if you start now. A realistic checklist:
- Inventory every Exchange server you own. Include VMs, DR copies, and any "we thought we decommissioned that" box in a closet. Note version, CU level, and whether it's internet-facing.
- Confirm your mailbox posture. If mailboxes are already in Microsoft 365 and Exchange is only there for hybrid management, your migration is mostly an identity and directory project, not a mail migration. Verify current recipient management and Entra Connect configuration before you plan the retirement.
- Pick a target and get a written plan. For most of our clients that means moving remaining mailboxes to Microsoft 365 and either decommissioning the last on-prem Exchange or moving to Exchange Server SE if you have a specific reason to stay on-prem. Do not assume — verify SE licensing terms with Microsoft or your reseller.
- Reduce your attack surface immediately. If you can't finish the migration before October, at minimum get Exchange off the public internet: front it with a reverse proxy, restrict OWA/ECP by IP, enforce MFA on any remaining admin paths, and make sure your EDR or MDR coverage on the server is actually reporting.
- Patch to the current CU and security update today. ESU is still shipping through October. Missing the latest fixes now is inexcusable.
- Update your compliance documentation. Whether it's your HIPAA risk analysis, your SOC 2 system description, or your CMMC SSP, note the migration plan and the interim compensating controls. Auditors and insurers will ask.
- Loop in your vCIO or IT strategy lead on budget. A rushed Q4 migration is more expensive than one scoped in July. If you don't have that role internally, our vCIO service exists precisely for decisions like this.

How PGH Networks can help
We've run Exchange-to-Microsoft 365 migrations for Pittsburgh professional services firms, CPA practices, healthcare offices, and defense contractors for years, and this cutoff is exactly the kind of deadline our managed IT and cloud teams plan around. If you're not sure what version you're on, whether your hybrid server is still needed, or how the migration lines up with your compliance obligations, we'll do the assessment and give you a written roadmap with real dates and real numbers — not a sales pitch.
Talk to us
Call 724.888.7007 or reach out through the contact form and we'll get an Exchange assessment on your calendar this week.
Related reading

Cybersecurity Services in Greentree, PA
Cybersecurity services in Greentree, PA for small and mid-market businesses: local response, EDR/MDR, HIPAA and CMMC support from a Pittsburgh MSP.

Cybersecurity for Financial Advisors in Pittsburgh
Cybersecurity for financial advisors in the Pittsburgh metro: SEC and FINRA aligned controls, 24/7 monitoring, and incident response from a local MSP team.

Managed Security Services Provider in Pittsburgh
Looking for a managed security services provider in Pittsburgh? See our 5-step process for 24/7 monitoring, EDR, compliance, and incident response.