Feeds.4Sysops Exchange Server August 2026 Update Disables OWA Light and Addresses Vulnerabilities
Article Content
- •The August 2026 update disables OWA Light and addresses a critical authentication bypass.
- •Only organizations enrolled in Extended Security Updates for Exchange Server 2016 and 2019 will receive updates.
- •A hybrid-deployment issue affecting shared mailboxes requires administrators' attention post-update.
Microsoft's August 2026 Exchange Server security update permanently disables the OWA Light client across all servers. This update addresses an authentication-bypass vulnerability demonstrated at Pwn2Own, affecting Exchange Server 2016 and 2019. Organizations must be enrolled in Period 2 Extended Security Updates to continue receiving updates. Additionally, the update exposes a hybrid-deployment issue impacting messages from shared mailboxes, requiring administrators to conduct post-update checks. The vulnerabilities could potentially allow unauthorized access to sensitive information if not addressed. The update is critical for maintaining security in affected systems, and organizations are urged to apply it promptly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Sets Oct. 11 Deadline for Patching Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after they were exploited by the China-linked group Flax Typhoon. Federal agencies must patch or retire the affected software by October 11, 2026. The vulnerabilities…