SECURITY

The Real Risks of Running Unsupported Exchange

Migration team · September 2026 · 9 min read

As of October 14, 2025, every traditionally licensed version of on-premises Exchange Server is out of support. Exchange 2010 fell out in October 2020, Exchange 2013 in April 2023, and Exchange 2016 and 2019 together in October 2025. The only supported ways to run Exchange today are Exchange Online in Microsoft 365 and the subscription-licensed Exchange Server Subscription Edition on-premises.

Plenty of businesses are still running one of the retired versions anyway, usually on the reasoning that it works fine and has for years. This article is for the owner or IT lead who needs to evaluate that reasoning honestly. Not scare copy: a sober inventory of what the risk actually is, where it shows up first, and why "it has been fine so far" is not the evidence it appears to be.

Risk 1: You are running a proven target with a frozen defense

The core problem with unsupported software is simple: vulnerabilities keep being discovered, and patches stop being written. For most software that is a theoretical concern. For Exchange it is not, because the last five years supplied a live demonstration of what Exchange exploitation at scale looks like.

In 2021, the vulnerability classes commonly called ProxyLogon and ProxyShell hit on-premises Exchange. Attackers automated the whole chain: scan the internet for Exchange servers, exploit them, plant web shells for persistent access. Compromise was not targeted at valuable victims; it was applied to essentially everything reachable, from global enterprises to ten-person firms, within days of the flaws becoming known. Microsoft shipped emergency patches, and even published mitigations for some already-retired versions because the situation was that severe. That episode is the template, not the exception: Exchange remains one of the most studied attack surfaces in enterprise software.

A supported server closes those windows within days of each discovery. An unsupported server never closes another one. The number of known, unpatched, forever-open flaws on your server only moves in one direction, and attackers specifically catalog end-of-life products because exploits against them never expire.

Why an Exchange compromise is worse than most

Risk 2: Your cyber insurance may quietly stop protecting you

Cyber insurers learned from the Exchange mass-exploitation era, and their applications now show it. It is standard for questionnaires to ask directly whether the organization runs end-of-life or unsupported software, and sometimes to ask about internet-facing servers specifically. That creates three bad outcomes and no good ones:

The uncomfortable math is that a migration frequently costs less than a single year's premium increase, and incomparably less than an uncovered incident.

Risk 3: Compliance findings and awkward customer questions

Most security and compliance frameworks require, in some form, that systems be supported and patched. Whether your obligation comes from HIPAA, PCI DSS, CMMC, SOC 2, state privacy law, or simply a large customer's vendor security questionnaire, an unsupported internet-facing mail server is a finding, and vendor questionnaires increasingly ask about it outright. Deals have stalled on exactly this answer. The regulatory exposure compounds after a breach: demonstrating that you knowingly ran unpatched end-of-life software handling personal data is not a position any counsel wants to defend.

Risk 4: The slow decay nobody announces

Security is the sharp risk. The dull one is that the ecosystem moves on and your server does not:

"It has been fine for years" is survivorship, not safety

The absence of a visible incident is weak evidence, for two reasons. First, mail server compromises are frequently silent by design: the attacker's goal is to read, not to announce. Second, risk that grows monotonically does not reward past luck. Every month adds newly discovered, never-to-be-patched flaws to the pile while your defense stays exactly where it was on the day support ended. The bet does not stay the same bet; it gets worse on a schedule you cannot see.

What the deadlines look like side by side

VersionExtended support endedUnsupported forDetailed guide
Exchange 2010October 13, 2020Nearly 6 yearsExchange 2010 five years on
Exchange 2013April 11, 2023Over 3 yearsExchange 2013 migration options
Exchange 2016October 14, 2025Almost 1 yearExchange 2016: what now
Exchange 2019October 14, 2025Almost 1 yearExchange 2019 paths compared

Closing the risk for good

Every risk in this article has the same single remediation: get mail onto a supported platform. For most organizations that means Exchange Online in Microsoft 365, where patching, uptime, and modern authentication are Microsoft's job. For the minority with hard data-residency mandates, it means Exchange Server Subscription Edition on-premises, kept current. Partial mitigations (VPN-only access, stricter firewalling, extra monitoring) buy time and are worth doing while you plan, but they narrow the exposure rather than ending it.

Getting there is a well-understood project when it is run by people who do it constantly. Ours follow the same shape regardless of version: a discovery that inventories everything touching mail, a fixed-price plan with dates, a staged or cutover move matched to your size and version, verification that nothing was lost, and a proper decommission of the old server so the risk actually ends rather than idling in a closet. The routes are mapped on our migration paths page, and we can stay on to manage the Microsoft 365 environment after cutover.

Unsupported Exchange is not a technology problem waiting for a convenient budget cycle. It is an open business risk with a known fix, a fixed price, and a short timeline. The only variable left is the date.

End the risk, not just the worry

Tell us what version you are running and how many mailboxes, and we will send back a fixed-price migration plan within one business day.

Plan My Migration