Trusted by more than 2500 companies with over 5 million users

December 2025 Exchange Server Security Updates Released

Microsoft has issued crucial security updates for Exchange Server, addressing multiple vulnerabilities across Exchange Server Subscription Edition (SE), Exchange Server 2019, and Exchange Server 2016. The December 2025 security updates patch several critical flaws, including CVE-2025-64666, an elevation of privilege vulnerability, and CVE-2025-64667, a spoofing vulnerability. SUs are available for the following specific versions of [...]

December 2025 Exchange Server Security Updates Released2025-12-10T04:06:42-05:00

Exchange Server SE Security – Why Firewalls Are Not Enough

Organizations running Exchange Server SE always utilize firewalls to help protect the environment. These range from very expensive comprehensive systems with many features to firewalls with very basic security controls. I’m always surprised by the very diverse deployments across the many customer systems we encounter.  Why Traditional Firewalls and Geo-Blocking Fall Short Some firewalls offer [...]

Exchange Server SE Security – Why Firewalls Are Not Enough2025-12-09T10:18:50-05:00

Thunderbird 145 Arrives with Native Microsoft Exchange Support

For years, users of the open-source email client Thunderbird have faced a common hurdle in corporate environments: Microsoft Exchange. While Thunderbird has always been a robust alternative to Outlook, connecting it to Exchange servers often required paid third-party add-ons (like Owl or ExQuilla) or relying on sometimes-fickle IMAP/POP configurations. With the release of Thunderbird 145, that [...]

Thunderbird 145 Arrives with Native Microsoft Exchange Support2025-11-25T08:57:46-05:00

Microsoft Exchange Server SE Security: 10 Critical Measures You’re Missing

The threat outlook for on-premises Microsoft Exchange servers has shifted from "constant monitoring" to "imminent threat." In a new joint advisory, the NSA, CISA, the FBI, and international partners (ASD’s ACSC and CCCS) have issued a stark warning: Exchange environments are continuously targeted by nation-state actors and cybercriminals. With the release of this guidance, it [...]

Microsoft Exchange Server SE Security: 10 Critical Measures You’re Missing2025-11-25T07:54:08-05:00

No Exchange Server Security Updates for November 2025

This month, Microsoft has announced that no security updates are being released for any version of Exchange Server in November 2025. This includes all customers using Exchange Server SE as well as those with Extended Security Updates (ESU) for Exchange Server 2019 and 2016. Microsoft reminds customers that although mainstream support for Exchange 2016 and 2019 has [...]

No Exchange Server Security Updates for November 20252025-11-18T10:55:37-05:00

CISA and NSA Issue Urgent Guidance to Secure Microsoft Exchange Servers

CISA and NSA have released urgent security guidance for organizations running Microsoft Exchange Server, warning that on-premises instances face imminent threats from nation-state attackers and cybercriminals. The joint advisory, developed with Australia's Cyber Security Centre and Canada's Cyber Centre, addresses persistent exploitation attempts targeting both Exchange servers and Windows Server Update Services (WSUS) infrastructure.​ Growing [...]

CISA and NSA Issue Urgent Guidance to Secure Microsoft Exchange Servers2025-11-04T01:58:35-05:00

Microsoft Announces Retirement of Office Online Server

Microsoft has officially announced the end of support for Office Online Server, effective December 31, 2026. This decision affects organizations that rely on on-premises browser-based document editing and viewing capabilities, pushing them toward Microsoft 365 or alternative solutions as they plan their migration strategies.​ What is Office Online Server Office Online Server was designed to provide [...]

Microsoft Announces Retirement of Office Online Server2025-10-28T09:28:53-04:00

Attackers Exploit Microsoft 365 Direct Send to Bypass Email Security and Deliver Phishing Attacks

Cybersecurity researchers have uncovered a widespread attack campaign exploiting Microsoft 365 Exchange Online's Direct Send feature, allowing threat actors to spoof internal users and deliver phishing emails without compromising a single account. Cisco Talos, Varonis Threat Labs, and multiple email security vendors report that over 70 organizations across various industries have been targeted since May [...]

Attackers Exploit Microsoft 365 Direct Send to Bypass Email Security and Deliver Phishing Attacks2025-10-23T10:11:40-04:00

October 2025 Exchange Server Security Updates Released

Microsoft has released critical security updates for Exchange Server, marking a significant milestone as these represent the final publicly available updates for Exchange Server 2016 and 2019. The October 2025 Security Updates (SUs) address multiple vulnerabilities across Exchange Server Subscription Edition (SE), Exchange Server 2019, and Exchange Server 2016.​ Affected Versions and Availability The October [...]

October 2025 Exchange Server Security Updates Released2025-10-15T07:57:17-04:00

Chinese Cyber Espionage Campaign Targets Foreign Ministries

Suspected Chinese hackers have infiltrated the Microsoft Exchange email servers of foreign ministries across Africa, the Middle East, and Asia in a sophisticated, multi-year espionage operation. Researchers at Palo Alto Networks' Unit 42 threat intelligence division revealed the discovery of Phantom Taurus, a previously undocumented nation-state actor conducting intelligence collection operations aligned with People's Republic [...]

Chinese Cyber Espionage Campaign Targets Foreign Ministries2025-10-03T04:13:38-04:00

Messageware EPG Now Fully Supports Exchange Server Subscription Edition (SE)

With Microsoft retiring support for Exchange Server 2016 and 2019 this month, Exchange Server Subscription Edition (SE) will become the only supported on-premises version. Microsoft has announced a 6-month Extended Security Update (ESU) program to give customers time to complete migrations. Messageware, a leading provider of security solutions for Microsoft Exchange, is pleased to confirm [...]

Messageware EPG Now Fully Supports Exchange Server Subscription Edition (SE)2025-10-02T04:35:46-04:00

Microsoft Exchange Server 2016 and 2019 Support Expires in Less Than One Month

Microsoft has issued a critical reminder that Exchange Server 2016 and Exchange Server 2019 will reach end of support on October 14, 2025, with less than one month remaining to prepare and act. Organizations must plan an immediate migration path to remain secure and compliant, either to Exchange Online or to the new Exchange Server Subscription Edition [...]

Microsoft Exchange Server 2016 and 2019 Support Expires in Less Than One Month2025-09-25T05:48:23-04:00

September 2025 Exchange Server Hotfix Updates Released

Microsoft has released the September 2025 Hotfix Updates (HUs) for Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE). These non-security updates address specific issues in earlier releases and include continued support for the dedicated Exchange hybrid app functionality. HUs are available for the following specific versions of Exchange Server: Exchange Server [...]

September 2025 Exchange Server Hotfix Updates Released2025-09-10T04:21:45-04:00

Messageware Announces AttachView Support for Exchange Server SE

Messageware is pleased to announce that Messageware AttachView is now fully compatible with Exchange Server SE, delivering complete Outlook Web attachment protection for organizations migrating to or running SE environments. As the only third-party solution purpose-built for Exchange Server SE, AttachView provides unmatched security for Outlook Web attachments. By instantly converting files into secure, browser-based [...]

Messageware Announces AttachView Support for Exchange Server SE2025-08-25T08:18:42-04:00

August 2025 Exchange Server Security Updates Released

Microsoft has released the August 2025 Security Updates (SUs) for Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE). These cumulative updates address multiple vulnerabilities and introduce default security hardening, and they explicitly include the capability required for on‑premises Exchange to support and use the dedicated Exchange hybrid app needed to mitigate [...]

August 2025 Exchange Server Security Updates Released2025-08-13T09:45:53-04:00

Critical Exchange Server Vulnerability Threatens Hybrid Cloud Environments

Microsoft has disclosed a high-severity vulnerability in Exchange Server hybrid deployments that poses significant risks to organizations worldwide. CVE-2025-53786, with a CVSS score of 8.0, enables attackers to escalate privileges from on-premises Exchange servers to connected cloud environments without leaving detectable audit trails. The Core Security Flaw The vulnerability exploits a fundamental design weakness in Exchange [...]

Critical Exchange Server Vulnerability Threatens Hybrid Cloud Environments2025-08-08T09:00:21-04:00

GhostContainer Backdoor Threatens Microsoft Exchange Security

A sophisticated new threat has emerged targeting Microsoft Exchange infrastructure worldwide. Kaspersky's Global Research and Analysis Team recently uncovered GhostContainer, a highly advanced backdoor malware that leverages open-source tools to establish persistent access to Exchange servers. This analysis examines the technical mechanisms, attack vectors, and implications of this threat for enterprise security teams managing Exchange deployments. GhostContainer [...]

GhostContainer Backdoor Threatens Microsoft Exchange Security2025-07-30T09:56:32-04:00

Chinese Hackers Exploit Microsoft SharePoint Zero-Day CVE-2025-53770: US Government Agencies Breached

A critical zero-day vulnerability in Microsoft SharePoint has triggered widespread cyberattacks across the globe, affecting businesses, government agencies, and educational institutions. The attack exploits a previously unknown security flaw that allows hackers to gain complete control over on-premises SharePoint servers without authentication. Microsoft has now directly attributed these attacks to Chinese state-sponsored hacking groups. Scale [...]

Chinese Hackers Exploit Microsoft SharePoint Zero-Day CVE-2025-53770: US Government Agencies Breached2025-07-29T06:45:06-04:00

Microsoft Announces Extended Security Update Program for Exchange Server 2016 and 2019

Microsoft has announced an optional 6-month Extended Security Update (ESU) program for Exchange Server 2016 and 2019, providing a temporary bridge for organizations struggling to complete their migrations before the upcoming end-of-support deadline. This program represents Microsoft's response to customer feedback indicating that some organizations need additional time to finalize their transitions to Exchange Subscription [...]

Microsoft Announces Extended Security Update Program for Exchange Server 2016 and 20192025-07-18T03:05:12-04:00