:

MICROSOFT ENDS EXCHANGE 2016/2019 SUPPORT

SECURITY DESK1 MIN READ
WED, JUL 22, 2026

■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE

Microsoft will discontinue security updates for Exchange 2016 and 2019 in October through its Extended Security Update program. Organizations running these versions must migrate to supported platforms.

Microsoft is phasing out security patches for Exchange 2016 and 2019, marking the end of the Extended Security Update (ESU) program for these versions. The deadline falls in October. Customers still relying on these older Exchange versions face increased security risks after the cutoff date. Microsoft recommends migrating to Exchange 2021 on-premises or Exchange Online in Microsoft 365. Exchange 2016 reached mainstream support end in October 2020, while Exchange 2019 reached mainstream support end in October 2023. The ESU program provided additional security updates beyond mainstream support periods. Organizations delaying migration should prioritize planning their upgrade path. Staying on unsupported versions exposes systems to unpatched vulnerabilities that attackers can exploit. Microsoft has provided extended timelines for customers to transition, with resources available on its support pages for migration planning.

■ SOURCES

Bleeping ComputerArs Technica

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

QBittorrent, the popular open-source torrent client, has been found capable of breaking out of sandbox environments to execute unauthorized operations. Security researchers identified the vulnerability, raising concerns about the application's access to system resources.

11H AGOIndustry Desk

Threat actors are deploying invisible Unicode characters in phishing campaigns to evade email security systems. The ASCII smuggling technique allows attackers to conceal malicious content from detection tools.

12H AGOSecurity Desk

A Unicode block invisible to human readers has transitioned from an academic curiosity used to test AI systems into an active tool for spammers. The technique exploits characters that machines process but humans cannot see.

17H AGOAI Desk

A study found that 86% of licensed British gambling websites violate GDPR privacy requirements, using deceptive cookie banners to track users before obtaining consent.

19H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.