Exchange Server August 2026 Update Disables OWA Light and Addresses Vulnerabilities

Exchange Server August 2026 Update Disables OWA Light and Addresses Vulnerabilities

First seen 12 Aug 2026, 14:37 UTC Feeds.4Sysops 79% similarity 70.5

Article Content

Browse articles
ThreatCluster

Microsoft's August 2026 Exchange Server security update permanently disables the OWA Light client across all servers. This update addresses an authentication-bypass vulnerability demonstrated at Pwn2Own, affecting Exchange Server 2016 and 2019. Organizations must be enrolled in Period 2 Extended Security Updates to continue receiving updates. Additionally, the update exposes a hybrid-deployment issue impacting messages from shared mailboxes, requiring administrators to conduct post-update checks. The vulnerabilities could potentially allow unauthorized access to sensitive information if not addressed. The update is critical for maintaining security in affected systems, and organizations are urged to apply it promptly.

Key Points: • The August 2026 update disables OWA Light and addresses a critical authentication bypass. • Only organizations enrolled in Extended Security Updates for Exchange Server 2016 and 2019 will receive updates. • A hybrid-deployment issue affecting shared mailboxes requires administrators' attention post-update.

ThreatCluster AI How this analysis works

Timeline

2026-08-12
Exchange Server August 2026 update released
Microsoft released a security update that disables OWA Light and fixes a Pwn2Own vulnerability affecting Exchange Server 2016 and 2019.
Feeds.4Sysops
2026-08-12
Hybrid mailbox bug identified
The update also exposes a hybrid-deployment issue affecting messages from shared mailboxes, necessitating checks by administrators.
Feeds.4Sysops

Community

Browse all →

Tracked Entities in This Story