9/4/2026
Rob

Microsoft Is About to Bounce Mail From Outdated Exchange Servers. There's a Live Vulnerability Too.

Here's the version of this story that should make every Exchange admin check their patch status today: Microsoft is about to start bouncing email from outdated on-premises Exchange servers, and at the same time there's a live vulnerability sitting on tens of thousands of machines that are still unpatched. It's not one story. It's two, and they're converging on the same deadline.

Let's start with the one that has a date attached. From the second week of September, Exchange Server 2016 and 2019 machines that send email to Exchange Online through an inbound connector of the OnPremises type must be patched to the final public update baseline released in October 2025. If they're not, Microsoft will throttle and then block their mail from reaching cloud-hosted inboxes. Microsoft's framing is blunt: "This update level was released almost a year ago, and all organizations should have updated to it." Microsoft detailed the change in an official Exchange Team blog post. The company has been advancing its "oldest acceptable version" for years, but this change takes the baseline to the final public update for Exchange 2016 and 2019. After this, the only way to stay current is the Extended Security Update program or a migration to Exchange Server Subscription Edition.

The scope matters, because this isn't a blanket block on every old server. Microsoft is clear that throttling and blocking apply only to servers sending email to Exchange Online through an inbound OnPremises connector. Other delivery methods are unaffected, and the policy doesn't necessarily cover every server in your organization. But then comes the line that should get your attention: "This might change in the future." That's Microsoft telling you the current carve-out is temporary, and the direction of travel is one way.

Now the second story, which is the one that should move you to act this week. A serious vulnerability designated CVE-2026-62911 was recently discovered in Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition. It can be exploited by hackers to gain full access to affected systems. Microsoft shipped patches in its August 2026 Patch Tuesday release, but according to The Shadowserver Foundation there are still 21,899 unpatched servers exposed. The highest concentrations are in the US and Germany, and the Netherlands National Cyber Security Centre and other agencies have urged admins to install the latest patches as soon as possible.

Put those two together and you get the real picture. The vulnerability is a reason to patch now. The baseline deadline is a reason to patch now. And the two are connected in a way that should worry anyone running a hybrid deployment: the servers most likely to be running old, vulnerable builds are the same ones that will suddenly find their mail bouncing when the September enforcement kicks in. If you've been putting off an Exchange update because of the risk that a patch breaks something — and Microsoft has, to put it delicately, caused problems in the past — the calculus has changed. The cost of not patching is no longer just a theoretical security risk. It's a concrete operational failure: mail stops flowing to your cloud-hosted inboxes.

The strategic tension here is the same one that runs through all of Microsoft's on-premises messaging. The company wants you on Exchange Online, and it's using a combination of security pressure and policy deadlines to get you there. The vulnerability is real, and the patches are necessary. But the enforcement mechanism — blocking mail from servers that don't meet a baseline — is also a lever to push organizations toward the cloud. That's not sinister, exactly. It's just the reality of running infrastructure that Microsoft controls the roadmap for. The question for most businesses isn't whether to move to Exchange Online eventually. It's whether they can survive the transition window without a gap in email service.

The practical takeaway is straightforward. If you run Exchange 2016 or 2019 on-premises, patch to the October 2025 baseline before the second week of September, and apply the August 2026 Patch Tuesday updates that address CVE-2026-62911. If you're on a hybrid deployment, verify which of your servers send through an OnPremises inbound connector, because those are the ones at risk of being blocked. And if you've been deferring a migration to Exchange Online, this is the moment to stop deferring — the window where Microsoft keeps the door open for old servers is closing.

The reality of running email infrastructure that has to keep working through a security patch, a policy deadline, and a migration all at once is the kind of problem that doesn't show up in a feature list. At DMC, we work with companies navigating exactly these constraints — patching on-premises Exchange, planning hybrid-to-cloud migrations, and making sure mail keeps flowing when the platform underneath you changes. Need help getting your Exchange estate in shape before the deadline? Let's talk.