Microsoft Exchange 2016 CU23 SU22
Microsoft Exchange 2016 CU23 SU22
The Microsoft Exchange 2016 CU23 SU22 reaches end of service life on Nov 1, 2026. Third-party support keeps it managed past that date — issue management, vulnerability remediation, and compliance maintenance from 24/7 engineers.
24/7 engineers own your Microsoft Exchange 2016 CU23 SU22 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- msexchange
- release
- 2016
- product Label
- Microsoft Exchange
- release Label
- 2016 CU23 SU19
- codename
- lts
- latest Version
- 15.1.2507.61
- release Date
- 2015-10-01
- maintained
- true
- source Url
- https://endoflife.date/msexchange
Lifecycle Dates
- End of Service Life
- Nov 1, 2026
- Last OEM Support
- Oct 13, 2020
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Microsoft Exchange 2016 CU23 SU22 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Microsoft Exchange 2016 CU23 SU22?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Microsoft Exchange 2016 CU23 SU22 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Microsoft Exchange 2016 CU23 SU22 Support: Frequently Asked Questions
Is the Microsoft Exchange 2016 CU23 SU22 still supported?
Yes, but Microsoft support for the Microsoft Exchange 2016 CU23 SU22 ends on Nov 1, 2026. You can upgrade on the vendor's schedule, or move to third-party support and keep the release you're on — issues managed, vulnerabilities remediated, compliance maintained.
When is the Microsoft Exchange 2016 CU23 SU22 end of service life (EOSL) date?
Microsoft lists the end of service life for the Microsoft Exchange 2016 CU23 SU22 as Nov 1, 2026.
Can I keep using the Microsoft Exchange 2016 CU23 SU22 after its EOSL date?
Yes. EOSL means Microsoft stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Microsoft Exchange 2016 CU23 SU22 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Microsoft Exchange 2016 CU23 SU22
167 published CVEs affect the Microsoft Exchange 2016 CU23 SU22, including 106 rated critical or high severity. Our 24/7 engineers help you assess exposure, prioritize fixes and apply available patches.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2024-21410 | CRITICAL | 9.8 | Feb 13, 2024 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2023-21709 | CRITICAL | 9.8 | Aug 8, 2023 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
| CVE-2021-28481 | CRITICAL | 9.8 | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-28480 | CRITICAL | 9.8 | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2019-1373 | CRITICAL | 9.8 | Nov 12, 2019 | A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'. |
| CVE-2019-0586 | CRITICAL | 9.8 | Jan 8, 2019 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. |
| CVE-2018-8302 | CRITICAL | 9.8 | Aug 15, 2018 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. |
| CVE-2018-8154 | CRITICAL | 9.8 | May 9, 2018 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151. |
| CVE-2026-55008 | CRITICAL | 9.6 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2021-34473 | CRITICAL | 9.1 | Jul 14, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-27078 | CRITICAL | 9.1 | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26855 | CRITICAL | 9.1 | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26412 | CRITICAL | 9.1 | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2020-17142 | CRITICAL | 9.1 | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability |
| CVE-2020-17132 | CRITICAL | 9.1 | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability |
| CVE-2022-21969 | CRITICAL | 9.0 | Jan 11, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2022-21855 | CRITICAL | 9.0 | Jan 11, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2022-21846 | CRITICAL | 9.0 | Jan 11, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26427 | CRITICAL | 9.0 | Oct 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-34523 | CRITICAL | 9.0 | Jul 14, 2021 | Microsoft Exchange Server Elevation of Privilege Vulnerability |
Showing the 20 most severe of 167 known CVEs.
Get Third Party Support