Skip to content
Pro IT NW

Blog · 13 min read ·

Share

SharePoint 2016 & 2019 EOL July 14, 2026: three paths

SharePoint Server 2016 and 2019 reached end of extended support July 14, 2026 — the deadline is now PAST. There is no ESU program for SharePoint at any price. Three actively-exploited vulnerabilities now sit against this stack: CVE-2026-56164 (privilege escalation, no fix for legacy versions), CVE-2026-50522 (CVSS 9.8 remote code execution, fixed only on the final day of support), and CVE-2026-55040 (authentication bypass, patched July 14, 2026 and added to CISA's Known Exploited Vulnerabilities catalog on August 18). Unmigrated farms are now permanently exposed.

Update — August 19, 2026: the exploit cycle is now shorter than a patch policy. CVE-2026-55040 is an authentication bypass in the JWT token validation of on-premises SharePoint Server. Rapid7 and Microsoft disclosed it jointly on July 14, 2026 — the same day SharePoint 2016 and 2019 went out of support — and Rapid7's public technical analysis followed on August 11. On August 18, CISA added it to the Known Exploited Vulnerabilities catalog. Rapid7's description of the impact is plain: a remote, unauthenticated attacker can bypass authentication on a vulnerable SharePoint server and then operate as a SharePoint site user or administrator.

The dates are the argument, not the CVE. Twenty-eight days from patch to public technical analysis. Seven more to a federal catalog entry that exists only where there is evidence of exploitation in the wild. Set your own remediation policy next to that sequence: if critical fixes get a 30-day SLA, the policy is now longer than the window between the patch shipping and the flaw being used. A compliant, on-time patch cycle can still leave you exposed for the part of the month that matters — and that is the good case, the one where a patch exists at all.

Which is the whole point of this post. An out-of-support SharePoint 2016 or 2019 farm does not get to be late on the next one. It gets no patch to be late with. Every argument below about migration timelines is really an argument about how many of these cycles you intend to sit through without a fix available.

⚠️ One thing not to repeat: the three-day remediation due date on that KEV entry does not bind you. It comes from Binding Operational Directive 26-04, which applies to federal civilian agencies, and a three-day window is the catalog's norm rather than a severity signal. The listing itself is the signal. We cover that distinction, and the triage you run after patching, in CISA KEV in 2026: patch, then assume compromise.
Update — August 3, 2026: a second exploited SharePoint flaw, and this one is worse. CVE-2026-50522 is a deserialization bug that, in NVD's words, "allows an unauthorized attacker to execute code over a network." It scores CVSS 9.8 Criticalnetwork reach, low complexity, no privileges, no user interaction — and CISA added it to the Known Exploited Vulnerabilities catalog on July 22, 2026. That is the second actively-exploited SharePoint vulnerability in a month, and it is a full remote-code-execution flaw rather than a privilege-escalation one.

Read the patch status carefully, because the nuance is the whole point. NVD lists fixed builds for 2016 (16.0.5561.1001), 2019 (16.0.10417.20175), and Subscription Edition (16.0.19725.20434) — so unlike the July elevation-of-privilege flaw described below, a fix does exist for the legacy versions here. Apply it. But understand what you are holding: both versions are now out of support with no ESU program, so there is no commitment that a fix will exist for the next one. The exposure is not this CVE. It is the one after it.

Also from July 2026: CVE-2026-56164, an elevation-of-privilege flaw (missing authentication, CWE-306) that lets an unauthenticated attacker reach Farm Administrator over the network with no credentials. Microsoft confirms active exploitation and CISA listed it. Its affected-products list includes 2016, 2019 and Subscription Edition — but a fix shipped only for the supported version. That is two actively-exploited SharePoint vulnerabilities in a month, and on the older one the legacy versions got nothing.

If your organization is still running SharePoint Server 2016 or 2019, the runway is gone: both versions reached end of extended support on July 14, 2026. (SharePoint 2016 mainstream support ended July 13, 2021; SharePoint 2019 mainstream ended January 9, 2024 — Microsoft aligned 2019's extended-support end date to 2016's.) There is no Extended Security Updates program for SharePoint Server. Exchange Server has a short paid ESU bridge that ends in October 2026; SharePoint has nothing of the kind. As of July 14, 2026, your SharePoint farm no longer receives security updates at any price — and, as the zero-day above shows, "no more updates" is not a slow problem. The goal now is a committed, scoped migration path with the security gap measured in weeks, not quarters.

Past the deadline — now what? A SharePoint Online migration for a 200-user farm runs 90–150 days end-to-end, so most organizations still on 2016/2019 cannot "catch up" instantly. The realistic goal is to get onto a committed, scoped path immediately and shrink the unsupported window — while treating the farm as actively at risk in the meantime (network-isolate where you can, watch it closely, and patch CVE-2026-50522 first — it is the more severe of the two and, unlike CVE-2026-56164, it has fixed builds for 2016 and 2019). The one option you do not have is "wait for ESU," because there isn't one.

There are exactly three real paths from here. This post walks each one with realistic timelines for 50-, 200-, and 500-user environments, the costs that actually show up in the budget, and the most common ways each path fails. It mirrors the format of our Exchange 2019 EOL post deliberately — the EOL decision tree is similar in shape, different in detail.

Where we actually are right now

MilestoneDateWhat it means
SharePoint Server 2016 mainstream EOS Jul 13, 2021 No more feature updates. Security updates only since this date.
SharePoint Server 2019 mainstream EOS Jan 9, 2024 No more feature updates. Security updates only since this date.
SharePoint Server SE released Nov 2021 Subscription Edition. In-place upgrade path from 2019 (2016 upgrades via 2019 first).
SharePoint 2016 and 2019 extended support ends Jul 14, 2026 Hard deadline for both versions. No ESU program. No security updates after this date at any price.

The contrast with Exchange Server is important: Exchange 2019 customers get a paid ESU bridge through October 2026. SharePoint 2019 customers do not. Your runway is shorter, and the "buy time with ESU" option that exists for Exchange does not exist for SharePoint.

Quotable stat: SharePoint Server 2019 has no Extended Security Updates program. Unlike Exchange Server, Windows Server, and SQL Server — all of which offer ESU bridges past extended support — SharePoint Server EOL was a hard deadline. July 14, 2026 was the last day patches were available.

Path 1: SharePoint Online — the right answer for most

Migrate every site collection, every document library, and every list to SharePoint Online. Reconfigure shared storage on OneDrive for Business with Known Folder Move (KFM). Decom the on-prem SharePoint farm — including SQL backends, search index, and any custom WFE servers.

This is the right answer for most organizations. The license you're already paying for in your Microsoft 365 plan covers SharePoint Online and OneDrive for Business. The operational cost of running an on-prem SharePoint farm — patching, SQL backup, search index health, custom solution maintenance, the tribal knowledge that lives in one engineer's head — is a tax you can stop paying.

Tooling: ShareGate vs Mover.io vs native

Three real options, each landing in a different scenario:

  • ShareGate Migrate — the mid-market and enterprise default. Strongest at preserving permissions, version history, customizations, and metadata across complex source farms. Per-user licensing with a tiered structure. The right answer when fidelity matters and when the source farm has any meaningful customization.
  • Mover.io (now part of Microsoft 365 Migration) — Microsoft's built-in tool, free with M365, strongest at file-share to OneDrive/SharePoint Online migrations. It is not the right tool for complex SharePoint-to-SharePoint moves with custom workflows and metadata. Good for the file-share leg of a hybrid project; not the SharePoint farm itself.
  • SharePoint Migration Tool (SPMT) — native — Microsoft's free SharePoint-specific tool. Adequate for simple migrations with minimal customization. Falls down on complex permission inheritance, InfoPath forms, and farm-solution WSPs.

Vendor-neutral framing: ShareGate is what we reach for on most mid-market engagements where source-farm customization is non-trivial. SPMT is the right call when the source farm is a near-vanilla 2019 install with minimal custom code. Mover.io owns the file-share leg. We don't resell any of them.

Realistic timelines

EnvironmentDiscoveryPilotCutoverHypercareTotal
50 users, ~5 site collections1 wk2 wks4–8 wks1 wk~60–90 days
200 users, ~25 site collections2 wks3 wks8–14 wks2 wks~90–150 days
500 users, ~75 site collections3 wks4 wks12–24 wks2 wks~150–240 days

Add 4–10 weeks if the source environment includes InfoPath forms (no automatic translation; rebuild as Power Apps), SharePoint Designer workflows (rebuild as Power Automate), or farm-solution WSPs (rebuild as SPFx). The customization tail is the dominant scheduling variable on most SharePoint migrations we've run.

File-share migration patterns: If your SharePoint 2019 environment also fronts older file shares — and most do — the file-share leg is its own sub-project. The pattern that works: target SharePoint document libraries for collaborative content, OneDrive with Known Folder Move for personal/desktop content, Azure Files SMB only for legacy-app dependency cases that can't move to SharePoint. Mixing these incorrectly is the most common mid-cutover slowdown.

Where Path 1 fails: teams under-scope the customization rebuild. InfoPath, Designer workflows, and farm solutions all need to be inventoried in week 1, not discovered in week 9. Permission inheritance on long-lived sites is also commonly a surprise — the source environment has 12+ years of accumulated inheritance breaks and explicit permissions that need rationalization before they get carried into SPO.

Path 2: SharePoint Server Subscription Edition

Microsoft released SharePoint Server Subscription Edition (SE) in November 2021. It's the on-prem continuation path — same deployment model, modern auth, subscription licensing instead of perpetual. In-place upgrade is supported from SharePoint Server 2019 with the most recent CU level.

Why might you choose this? You have a real reason to keep SharePoint on-premises:

  • CMMC Level 3 or other US defense data-handling requirements that mandate on-prem or sovereign-cloud workloads
  • Regulated financial services with jurisdictional rules requiring on-prem document storage
  • EU data residency mandates that aren't satisfied by Microsoft 365's EU Data Boundary for the specific data class in scope
  • Air-gapped or sovereign-cloud environments where SharePoint Online is not an option

Outside those scenarios, SharePoint SE is rarely the right answer despite being the on-prem continuation. The license-plus-hardware-plus-operations math almost always loses to SharePoint Online once you account for what's already included in the M365 plans you're paying for. We've watched several mid-market customers commit to SE because "we already have the team for it" and regret it 18 months later when the SQL upgrade, the hardware refresh, and the SE CU cycle all hit at once.

What the upgrade actually requires

  1. SharePoint Server 2019 must be on the most recent CU. If you're behind, plan for the CU sequence first.
  2. Hardware refresh. SharePoint SE's published hardware requirements are higher than 2019. If your farm is on hardware that's been live since 2019, plan for replacement.
  3. SQL Server upgrade. SharePoint SE supports newer SQL versions. Plan the SQL upgrade as a parallel project.
  4. Modern auth integration. SharePoint SE supports modern authentication via OIDC. If your farm is on classic auth (NTLM/Kerberos only), the upgrade is also a modernization.
  5. Custom solutions audit. Farm-solution WSPs may not be supported in SE the same way. Audit each one against the SE supportability matrix before the upgrade.

Realistic timeline: 8–16 weeks for the upgrade itself, assuming hardware is procured and SQL is in a known state. Plan for Cumulative Updates every 6–8 months indefinitely. This is a real ongoing commitment, not a one-time project.

Reality check: if you're considering SharePoint SE because "we've always done it this way," that's inertia, not a reason. Run the three-year TCO honestly. Hardware + Windows Server CALs + SQL Server + backup + patching labor + the M365 plan you're already paying for is almost always more expensive than just moving to SharePoint Online. The data-sovereignty cases above are real; the inertia case is not.

Path 3: SharePoint hybrid + selective workloads

Keep SharePoint Server 2019 (upgraded to SE for security continuity) for specific workloads — heavy customizations, LOB applications with hard SharePoint integration, or content classes that genuinely cannot move to SPO. Migrate the rest to SharePoint Online. Run the two in a hybrid configuration with SharePoint hybrid search and federated navigation.

This is the most complex path. It is the right answer in a narrow set of scenarios:

  • Specific LOB apps that integrate via SharePoint server APIs (full-trust solutions, server object model dependencies) and have no migration roadmap to SPO
  • Content classes that the business explicitly cannot move to SPO (regulated, sovereignty-constrained) where the rest of the environment is moving
  • Phased migrations where the on-prem retention is a transition state, not a permanent endpoint

What hybrid actually means in practice

  • An on-prem SharePoint Server SE farm running the workloads that stay on-prem
  • SharePoint Online for everything that moved
  • SharePoint hybrid configuration providing federated search across both, hybrid OneDrive redirection, and hybrid extranet sites if needed
  • Entra Connect with synchronized identities (already in place for most M365 customers)

Hybrid is a long-term operational commitment. You're running both farms — patching both, monitoring both, integrating both — and you're carrying the customization tail of the on-prem environment indefinitely. It's the right answer when the cost of forcing migration of the held-back workloads exceeds the cost of running hybrid. It is rarely the right answer when the held-back workloads could be modernized given two more quarters of rebuild work.

Where Path 3 fails: the held-back workloads were always going to be migrated eventually, and the hybrid posture extends the project's runway by years rather than months. If "selective hybrid" becomes "permanent hybrid because nobody got around to finishing the migration," you're paying for two environments forever. Set a sunset date for the on-prem remainder when you scope Path 3, not when the hybrid posture has been live for three years.

SharePoint 2019 End of Support: It Already HappenedWatch on YouTube (opens in a new tab)

The decision tree, simplified

Your situationRight path
Most users, no regulatory constraint blocking cloud Path 1 (full SharePoint Online migration)
CMMC L3 / sovereign-cloud / regulatory mandate to keep on-prem Path 2 (SharePoint SE)
Heavy custom WSPs or LOB integrations + cloud-blocked subset Path 3 (selective hybrid, with sunset date)
"We have time" / "We'll figure it out next year" You don't have time. ESU does not exist for SharePoint.

What we recommend doing this week

  1. Inventory. Confirm SharePoint version and CU, site-collection count, document and list counts, customization footprint (InfoPath forms, Designer workflows, farm-solution WSPs, SPFx solutions), third-party integrations, and storage footprint per site collection. Most environments don't have an accurate inventory and that's the source of every blown SharePoint migration.
  2. Decision committee. IT director, CIO, security/compliance, and any LOB application owner with a SharePoint-server dependency. Walk the three paths. Commit to one with a sunset date for any retained on-prem footprint.
  3. Engage scope. Whether the work is in-house or with a consultancy, get a written scope on paper with a timeline, a budget, and acceptance criteria. The total fixed-fee labor for Path 1 ranges from $20K (50 users) to $80K (500 users) depending on customization tail.

Common mistakes we see right now

Treating the customization tail as a "we'll figure it out" item

InfoPath forms, SharePoint Designer workflows, and farm-solution WSPs do not migrate themselves. The decision isn't "do we move them" — it's "do we rebuild them, retire them, or keep them on-prem." That decision needs to happen in week 1, with the business owner of each customization in the room.

Skipping the file-share story

Most SharePoint 2019 environments also front older file shares. The file-share migration is its own project with its own tooling and its own change-management overhead. Bake it into the SharePoint scope or run it as a parallel track — but don't pretend it's a side conversation.

Buying SharePoint SE because it feels safer

On-prem SharePoint feels safer to teams who've operated SharePoint farms for a decade. The three-year TCO math almost never agrees with that feeling. SharePoint SE is the right answer when sovereignty mandates it, not when it's emotionally familiar.

Treating July 14, 2026 as "extended support" the way Exchange does

There is no SharePoint ESU program. The deadline is hard. If your "plan" is "we'll buy ESU like we did with Exchange," there is no ESU to buy. Re-plan accordingly.

Related reading

One more thing: SharePoint wasn't the only product that died that day

Scoping conversations tend to start and end with SharePoint, and then the project plan grows in week three. Microsoft's 2026 end-of-support list puts all of the following on July 14, 2026 — the same date:

  • SharePoint Server 2016 and SharePoint Server 2019
  • Project Server 2016 and Project Server 2019 — these ride on SharePoint, and teams routinely forget they are separate products with their own support dates
  • SQL Server 2016 — very often the database tier underneath the farm you are migrating
  • SQL Server 2014, Extended Security Updates Year 2
  • SharePoint Designer 2013 and InfoPath 2013 — still load-bearing in more mid-market workflows than anyone likes to admit

The practical consequence: if your SharePoint farm runs on SQL Server 2016, both tiers went out of support on the same day, and they do not have the same escape route. SQL Server 2016 has a paid Extended Security Updates ladder that started July 15, 2026 and runs in three annual steps to July 2029 — and note that it is genuinely paid. Microsoft states that starting with SQL Server 2016, moving a workload to SQL Server on Azure VMs no longer provides free access to ESUs; that concession applies to SQL Server 2014, not 2016. SharePoint Server has no ESU program at any price. So the database can be bought time, at a price; the farm cannot be bought time at all. We covered what those ESUs actually cover, what they cost, and the four remaining paths in SQL Server 2016 end of support: ESU or upgrade?. Scope both tiers before you commit to a date, and check whether InfoPath forms or SharePoint Designer workflows are quietly in the critical path — those are the two that turn a clean migration into a rebuild.

Sources and further reading

The 30-second version

SharePoint Server 2016 and 2019 both reached end of support on July 14, 2026 — that date has passed. There is no ESU program for SharePoint at any price. Three real paths: SharePoint Online for most, SharePoint SE for sovereignty-constrained workloads, selective hybrid only with a written sunset date. The customization tail (InfoPath, Designer workflows, farm-solution WSPs) is the dominant scheduling variable. Inventory this week, decide next week, scope by end of month.

If you'd like a senior engineer to walk through it with you, the project intake form takes about three minutes. We'll come back with scope and a fixed-fee range.


Pro IT NW does senior-led Microsoft project work. Vendor-neutral. Labor-only. Based in Seattle, delivered USA-wide. We don't take resale margins on SharePoint, ShareGate, or any of the destinations in this post.

Questions we get asked

When do SharePoint Server 2016 and 2019 reach end of life?
Both reached end of extended support on July 14, 2026 — Microsoft aligned SharePoint Server 2019's end date with 2016's. SharePoint 2016 mainstream support ended July 13, 2021; SharePoint 2019 mainstream ended January 9, 2024. Unlike Exchange Server — which has a short paid ESU bridge ending October 2026 — SharePoint Server has no Extended Security Updates (ESU) program at all. As of July 14, 2026, no security updates are available at any price.
Is there an actively exploited SharePoint vulnerability in 2026?
Three as of August 2026. On July 14, 2026 — the same day SharePoint 2016 and 2019 reached end of support — Microsoft disclosed CVE-2026-56164, an elevation-of-privilege flaw caused by missing authentication for a critical function (CWE-306), letting an unauthenticated attacker reach Farm Administrator over the network. Microsoft patched supported SharePoint but not the out-of-support versions. Then CVE-2026-50522, a deserialization bug allowing unauthenticated remote code execution at CVSS 9.8, was added to CISA's Known Exploited Vulnerabilities catalog on July 22, 2026. That one does have fixed builds for 2016 and 2019 — but they shipped on the last day those versions were supported, so it is likely the final security update they will ever receive. The third is CVE-2026-55040, an authentication bypass in on-premises SharePoint Server's JWT token validation that Rapid7 and Microsoft disclosed with a fix on July 14, 2026; Rapid7 published its technical analysis on August 11, 2026 and CISA added the CVE to the Known Exploited Vulnerabilities catalog on August 18, 2026.
What is CVE-2026-55040?
CVE-2026-55040 is an authentication bypass in the JWT token validation of on-premises SharePoint Server. Rapid7 and Microsoft disclosed it jointly on July 14, 2026, the day the fix shipped. Rapid7 published its technical analysis on August 11, 2026, describing the impact as a remote, unauthenticated attacker bypassing authentication on a vulnerable SharePoint server and then performing operations as a SharePoint site user or administrator. CISA added it to the Known Exploited Vulnerabilities catalog on August 18, 2026, which is the point at which there is evidence of exploitation in the wild. One thing not to misread: the remediation due date attached to a KEV entry comes from Binding Operational Directive 26-04 and binds Federal Civilian Executive Branch agencies. It is not a legal deadline for a private company, and a short window is the catalog's normal shape rather than a severity signal. Check your own farm's patch state against Microsoft's advisory for the CVE, not against a version list in an article.
What can an out-of-support SharePoint farm actually do about a vulnerability like CVE-2026-55040?
Less than you would like, and that gap is the argument for migrating rather than a reason to despair. SharePoint Server 2016 and 2019 reached end of extended support on July 14, 2026 and have no Extended Security Updates program at any price, so for the next vulnerability in this product there is no fix to apply late — there is no fix. Until the farm is migrated, everything available is a compensating control: take the farm off the public internet, put authentication in front of it with a VPN or an authenticating reverse proxy, restrict and review farm-administrator access, monitor authentication logs for the anomalies you would look for after a compromise, and confirm your backups actually restore. Those measures reduce reachability and shorten dwell time. None of them substitutes for a patch, and all of them are stopgaps for a migration that still has to happen.
What else reached end of support on July 14, 2026?
More than SharePoint, which is why the migration scope is usually bigger than teams expect. Microsoft's 2026 end-of-support list puts SharePoint Server 2016, SharePoint Server 2019, Project Server 2016, Project Server 2019, SharePoint Designer 2013, InfoPath 2013, SQL Server 2016, and SQL Server 2014 Extended Security Updates Year 2 all on the same date. If your SharePoint farm sits on SQL Server 2016, both tiers of that stack went out of support the same day. SQL Server 2016 at least has a paid three-year ESU ladder that began July 15, 2026; SharePoint has nothing equivalent at any price.
What are the migration paths from SharePoint Server 2019?
Three real paths: (1) full migration to SharePoint Online — the right answer for most organizations; (2) in-place upgrade to SharePoint Server Subscription Edition (SE) for organizations with regulatory data-sovereignty requirements; (3) selective hybrid — keep SharePoint 2019 for specific workloads with hard customizations or LOB integrations and move the rest to SPO.
How long does a SharePoint 2019 to SharePoint Online migration take?
For 50 users, 60–90 days end-to-end. For 200 users, 90–150 days. For 500 users, 150–240 days. The dominant variable is custom code and third-party solution dependencies — every InfoPath form, every farm-solution WSP, every workflow that doesn't translate cleanly to Power Automate adds time.
What does SharePoint Server Subscription Edition cost compared to SharePoint Online?
SharePoint SE is licensed per server plus per user CAL on a subscription model. For most mid-market environments, the three-year TCO of SharePoint SE — including hardware refresh, Windows Server licensing, SQL Server, backup, patching labor, and Microsoft 365 plans you're already paying for — runs 2–3x the SharePoint Online line item already included in most M365 plans. SE is the right answer when data sovereignty mandates it, not when it's cheaper, because it usually isn't.

Written by the team at · Senior-led Microsoft project consultancy · Seattle and the Pacific Northwest, delivered USA-wide.

Moving off SharePoint Server 2016 or 2019?

Senior Microsoft engineers based in the Pacific Northwest — onsite around Puget Sound, remote anywhere in the US. Tell us the environment and the deadline, and we'll scope it as a fixed-fee project.