HACKED24, Autonomous Enterprise IT

DACH still runs Exchange and SQL Server past their end of support

Most German on-prem Exchange servers run unsupported versions, and the last paid patches end in October 2026. Why they stay, and what to decide now.

David Lorenz
Oct 8, 20266 min read
A brushed aluminium hexagonal server block with a white ceramic top plate and a thin indigo to cyan light seam, on a light grey background.

Key points

  • In October 2025, 92% of around 33,000 on-premises Exchange servers known to the German BSI ran unsupported versions.
  • The paid Exchange 2016 and 2019 ESU ends with October 2026, and Microsoft has said there will be no further extension.
  • Nobody knows how many SQL Server 2016 and older instances run in DACH, because most are invisible to internet scans.
  • Real dependencies and a budget logic that rewards waiting keep them running, and NIS2 makes that a management decision.

Exchange Server end of support for 2016 and 2019 was October 14, 2025. 2 weeks later the German Federal Office for Information Security (BSI) published its count: around 33,000 on-premises Exchange servers known in Germany, 92% of them on version 2019 or older with Outlook Web Access exposed. On August 28, 2026, CERT-Bund said around 85% of on-premises Exchange servers in Germany were still vulnerable to CVE-2026-62911, and it knew of only 9 servers running 2016 or 2019 with Extended Security Update (ESU) patches installed (heise, August 31, 2026).

Our reading: in the DACH region, end of support is a date in a lifecycle table, not a decision. SQL Server 2016, out of extended support since July 14, 2026, follows the same pattern.

Exchange Server end of support has not reduced the installed base in Germany

In March 2024 the BSI reported at least 17,000 of around 45,000 internet-facing Exchange servers in Germany as critically vulnerable, about 12% on Exchange 2010 or 2013 (The Register, March 28, 2024). In October 2025 the outdated share was 92%. No newer total has been published.

The ESU was meant as a bridge. Period 2 covers Exchange 2016 CU23 and 2019 CU14 or CU15, is bought separately under an Enterprise Agreement, and ends with October 2026; Microsoft states there will be no further extension (Microsoft Exchange Team, 2026).

Austria and Switzerland publish warnings, not version statistics. CERT.at warned on August 27, 2026 that exploit code for CVE-2026-62911 was public and that the Exchange 2016 fix ships only through ESU (CERT.at). The Swiss NCSC, now BACS, last published a count in February 2023: more than 600 servers still vulnerable to ProxyNotShell (NCSC). Shadowserver counted nearly 22,000 servers unpatched against CVE-2026-62911 worldwide, 5,100 in Germany (Help Net Security). We found no current version count for Austria or Switzerland, and we do not estimate one.

Product End of support Paid security updates
Exchange Server 2010 October 13, 2020 None
Exchange Server 2013 April 11, 2023 None
Exchange Server 2016 and 2019 October 14, 2025 ESU Period 2 until end of October 2026, no extension
SQL Server 2012 July 12, 2022 ESU ended July 2025
SQL Server 2014 July 9, 2024 ESU until July 2027
SQL Server 2016 July 14, 2026 ESU until July 17, 2029, paid in every year

Nobody knows how many old SQL Servers run in DACH

For SQL Server there is no BSI, CERT.at or BACS figure that we could verify. Internet scans only see exposed instances, and a correctly built SQL Server sits behind a firewall. The real installed base of SQL Server 2016 and older in the region is unknown.

What is known is the price of staying. SQL Server 2016 ESUs are paid in every year, also on Azure VMs, and need Azure Arc unless bought through volume licensing for a disconnected server. Late subscribers pay back to the start of the term, and Express editions have no ESU path (Microsoft Learn, ESU FAQ).

Old servers stay because the dependencies are real

Our assessment of a typical environment: Exchange is more than the mailbox server. Scanners, ERP and monitoring relay SMTP through it, and public folders hold data nobody wants to migrate. Many hybrid tenants still keep a server for recipient management. Removing the server touches each flow, and each has a different owner.

SQL Server is tied tighter. ERP and industry software is often vendor certified for specific SQL versions and compatibility levels. If the next SQL release is certified only with a new application release, the database upgrade becomes an application project, and that is where it gets postponed.

In November 2022 the German Data Protection Conference (DSK) concluded that controllers cannot demonstrate a data protection compliant use of Microsoft 365 on the basis of Microsoft’s contract terms at that time (DSK, November 24, 2022). That assessment still slows Exchange Online decisions in works council and procurement discussions.

Staying on premises also changed price. Microsoft requires subscription licences or licences with active Software Assurance for the current Exchange Server, servers and CALs (Microsoft Product Terms). For companies that bought Exchange 2016 perpetual without SA, staying on premises becomes a recurring cost. Add a thin market for Exchange hybrid and SQL specialists, and the budget logic is simple: it still runs, so it moves to next year.

NIS2 makes old servers a management decision

Germany’s NIS2 implementation act was published on December 5, 2025 (BGBl. 2025 I Nr. 301) and applies without a transition period. Management of covered entities must approve and oversee risk management measures. Austria’s NISG 2026 (BGBl. I Nr. 94/2025) applies from October 1, 2026 with a similar oversight duty.

An internet-facing mail server without security updates is hard to defend as an appropriate measure to an auditor or a supervisor. Whatever the company declared to its insurer about patching must also match reality, see cyber insurance requirements. The BSI warns that a compromised Exchange server often leads to the whole network, so Active Directory recovery belongs in the same discussion.

Note

As of October 8, 2026. Whether your organisation is covered by NIS2UmsuCG or NISG 2026, and which obligations apply, depends on sector and size. Check the law texts linked here with your legal counsel. This is not legal advice.

What to do now

  1. CIO: Within 30 days, inventory every Exchange and SQL Server instance with version, edition, ESU status, internet exposure and dependent applications, including Express instances and SMTP relays.
  2. CISO: Before the end of October 2026, restrict Exchange web services on every 2016 or 2019 server to VPN or trusted source addresses, as the BSI recommends.
  3. CIO: Decide per system: Exchange Online, Exchange Server Subscription Edition (SE) or decommission. For SQL: upgrade, Azure Arc ESU as a dated bridge, or Azure SQL Managed Instance where the vendor supports it.
  4. CFO: Compare ESU and Software Assurance cost with migration cost over 3 years, and approve no ESU renewal without an end date.
  5. Board: Give every system that cannot be replaced yet a named owner and a shutdown date, isolate it, and review the list quarterly.

At HACKED24 we start with read access: we inventory Exchange, SQL Server and their dependencies and give management a decision list with cost, risk and an owner per system. This is part of our Executive IT & AI Review, with delivery under our Microsoft Platform Services.

David Lorenz

Founder and Managing Partner of HACKED24. More than 20 years in enterprise IT architecture, security and operations.

Want to see what this means for your IT?

Every enquiry is answered personally, usually on the same business day.