511,000+ End-of-Life Microsoft IIS Instances Exposed Online, Secure Now!
An extensive number of outdated Microsoft Internet Information Services (IIS) servers have been identified as vulnerable. On March 23, 2026, Shadowserver's daily network scans revealed over 511,000 End-of-Life (EOL) IIS instances actively connected to…
An extensive number of outdated Microsoft Internet Information Services (IIS) servers have been identified as vulnerable. On March 23, 2026, Shadowserver's daily network scans revealed over 511,000 End-of-Life (EOL) IIS instances actively connected to the internet.
This widespread exposure presents a significant security risk for organizations worldwide, as these servers no longer receive standard security patches. Attackers frequently scan the internet for unpatched infrastructure to exploit known vulnerabilities, deploy malware, or gain initial access to corporate networks.
The data shared by Shadowserver highlights global internet infrastructure vulnerabilities. Of the 511,000 exposed EOL instances, over 227,000 have exceeded the Microsoft Extended Security Updates (ESU) period . These servers are End-of-Support (EOS) and will not receive critical security fixes, even with extended coverage.
Geographically, the exposure is most significant in China and the United States, which host the highest number of these outdated IIS instances.
An extensive number of outdated Microsoft Internet Information Services (IIS) servers have been identified as vulnerable.
To assist security teams, Shadowserver now tags vulnerable servers as 'eol-iis' and 'eos-iis' in its daily Vulnerable HTTP reports.
Network administrators can access this data to identify exposed assets within their environments. Operating EOL and EOS web servers increases an organization’s vulnerability to cyberattacks. When software reaches the end of its lifecycle, the vendor ceases monitoring it for security flaws. If a new zero-day vulnerability is discovered in an outdated version of IIS, Microsoft will not release a patch. Threat actors exploit this by developing tools to detect and exploit these systems.
The Cybersecurity and Infrastructure Security Agency (CISA) warns about the risks associated with end-of-support edge devices. Exposed web servers often serve as entry points for ransomware operators and Advanced Persistent Threat (APT) groups. Once an attacker compromises an IIS server, they can further infiltrate the internal network, steal data, or deploy malicious payloads .
Organizations must prioritize securing their internet-facing infrastructure to prevent exploitation. Security teams should follow these steps to effectively reduce their attack surface:
Audit external network assets to locate servers running legacy versions of Microsoft IIS. Review Shadowserver's Vulnerable HTTP reports to identify exposed IPs associated with the organization. Upgrade EOL servers to supported versions of Windows Server and IIS. Enroll systems in Microsoft’s Extended Security Update program if immediate migration is not feasible. Isolate legacy systems behind robust web application firewalls and restrict access to essential IP addresses.
Based on reporting by Cyber Security News.
