Exchange 2016 CU23 SU22 EOL Oct 14, 2025 – Risks & Support
The End: October 14, 2025 for Exchange 2016 CU23 SU22
If you are still running Microsoft Exchange 2016 Cumulative Update 23 (CU23) with Security Update 22 (SU22), the vendor support clock has stopped. As of October 14, 2025, this specific build is past its end-of-life date. This article is a practical reference for anyone operating this version today or finding it in production months or years from now.
What Happened on October 14, 2025
End of life means Microsoft will no longer provide:
- Security patches – No new fixes for vulnerabilities, including critical remote code execution flaws.
- Hotfixes – No resolution for non-security bugs, even for data loss or service outages.
- Support tickets – Microsoft support cases for this build will be declined or redirected to an upgrade.
- Updates – No cumulative updates, security updates, or rollups.
End of active support for Exchange 2016 occurred earlier, on October 13, 2020. After that date, you already needed a paid Extended Security Updates (ESU) subscription to get security patches. CU23 SU22 was the last build that could receive those ESU patches. Now that build itself is retired.
Note: Exchange 2016 is not an LTS (Long-Term Servicing Channel) release. It uses a standard lifecycle model. There is no extended support path beyond what was offered via ESU.
What Still Works
Your Exchange 2016 CU23 SU22 servers will continue to function. Mail flow, calendar, and user access will not stop. The software will not self-uninstall. What stops is the vendor safety net. This is a key distinction: the system runs, but it is now running without a manufacturer security guarantee.
The Real Risks of Running It Unsported
Vulnerabilities discovered after October 14, 2025 will never be patched for this build. Attackers know this. Common risks include:
- Remote code execution – Exchange is a frequent target for zero-day and unpatched exploits.
- Data exfiltration – Attackers can move laterally from a compromised Exchange server to the rest of the network.
- Compliance exposure – Auditors and regulators (PCI DSS, HIPAA, GDPR, SOX) often require supported, patched software.
Why Some Organizations Stay on This Build
Not every shop can upgrade overnight. Legitimate reasons for remaining on Exchange 2016 CU23 SU22 include:
- Stable workloads – The system is running a narrowly scoped, reliable function (e.g., internal journaling or archive-only mailboxes) and upgrading introduces change risk.
- Locked application dependencies – A line-of-business application integrates directly with Exchange Web Services or MAPI and has not been re-certified with a newer version.
- Hardware constraints – The existing physical or virtual infrastructure cannot support the OS or .NET requirements of Exchange 2019 or Exchange Online.
How Third-Party Support Keeps It Safe
When the vendor stops, third-party maintenance can fill the gap. Providers like 3rd Party Support offer:
- Security patches – Custom hotfixes for critical vulnerabilities discovered after vendor end-of-life, delivered per a commercial SLA.
- Bug fixes – Resolution for functional issues (transport, calendar, authentication) that would otherwise be unfixable.
- Technical support – Engineer-level assistance for break/fix, configuration, and performance tuning.
- Cost control – This coverage often costs a fraction of the last Microsoft renewal or the license cost of upgrading.
For many organizations, third-party support is the most practical path to keep Exchange 2016 CU23 SU22 running securely for another 3–5 years while planning a longer-term displacement.
Are You Still on This Build?
If you discovered this article months or years after October 2025 and you are still running Microsoft Exchange 2016 build 15.1.2507.69 (the latest version of this line), you are now unsupported from a vendor perspective. Evaluate your exposure and consider a support path that matches your risk tolerance.
Contact us to discuss how we can extend the safe operational life of your Exchange 2016 environment.
Lifecycle source: endoflife.date/msexchange
Get support for what you run
How we can help
Keep it supported after end of life
The vendor's date doesn't have to be yours. Our engineers keep Microsoft Exchange 2016 CU23 SU22 running after official support ends — independent third-party support that covers most operational issues, typically at 40-70% below the last renewal quote.
Microsoft software support →Migration services
When you do decide to move, we plan and execute the migration. Your current environment stays under vendor support while your contract is active — and if the renewal lapses mid-move, our third-party support covers most issues until the last workload is off it.
Migration & hybrid cloud services →24×7 remote administration
Short on hands to run it day to day? Our NOC engineers monitor, patch and administer your environment around the clock — incident response included, at a fraction of the cost of an in-house night shift.
24/7 operations & remote administration →More EOSL Alerts
VMware Site Recovery Manager 9.0: EOL September 2027
VMware Site Recovery Manager 9.0 reaches end of life on September 17, 2027. Learn what that means for your budget, migration timelines, and third-party support
August 17, 2026
VMware Cloud Foundation 9.0 EOL September 2027
Plan your budget now: VMware Cloud Foundation 9.0 ends support Sept 17, 2027. Compare upgrade, vendor extended support, and third-party support costs to stay se
August 17, 2026
VMware ESXi 9.0 EOL September 2027
VMware ESXi 9.0 ends support Sept 17, 2027 – 13 months away. Plan next year's budget: compare migration costs with third-party support savings of 40–70%.
August 17, 2026