Patch/Configuration Management Microsoft ends extended security updates for Exchange 2016 and 2019 in October 2026 July 22, 2026 Share By SC Staff Microsoft has issued a reminder to its customers that extended security updates (ESU) for Exchange Server 2016 and 2019 will cease in October 2026. This follows a six-month extension to the original ESU program, which began after the servers reached their end of support, based on information published by Bleeping Computer. The Exchange Server team confirmed that there will be no further extensions beyond the current Period 2 ESU program, which concludes in October 2026. Even customers enrolled in this extended program will not receive updates after this date. Microsoft is advising IT administrators to upgrade to Exchange Server Subscription Edition (SE) or migrate to Microsoft 365. For those still running Exchange 2016 or older, direct upgrades to SE or an intermediate upgrade to Exchange 2019 are recommended before migrating. This move impacts organizations relying on these older versions of Exchange, necessitating a transition to newer, supported platforms to maintain security and receive ongoing patches. The company has also recently extended support for Windows 10 consumers and is transitioning Windows Server 2022 and certain Windows 11 editions to extended support. Source: Bleeping Computer SC Staff Related Patch/Configuration Management Windows 10 devices carry 3 times the risk of Windows 11, data shows SC Staff July 17, 2026 New data from Lansweeper indicates that approximately 16.9% of Windows client devices, or one in six, continue to operate on Windows 10. Patch/Configuration Management Microsoft pauses Windows 11 update for Dell PCs due to compatibility issues SC Staff July 17, 2026 The update, released on July 14, was halted after reports indicated that a number of Dell devices displayed a yellow exclamation point next to the Intel Innovation Platform Framework Processor Participant driver in Device Manager. Vulnerability Management Critical Oracle EBS bug added to CISA list of exploited vulnerabilities Laura French July 17, 2026 The flaw allows an unauthenticated attacker to remotely compromise Oracle Payments. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds