Skip to content
Exchange Server August 2026 Update Disables OWA Light and Addresses Vulnerabilities

Exchange Server August 2026 Update Disables OWA Light and Addresses Vulnerabilities

First seen 12 Aug 2026, 14:37 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 13, 2026 at 14:22 UTC
  • •The August 2026 update disables OWA Light and addresses a critical authentication bypass.
  • •Only organizations enrolled in Extended Security Updates for Exchange Server 2016 and 2019 will receive updates.
  • •A hybrid-deployment issue affecting shared mailboxes requires administrators' attention post-update.

Microsoft's August 2026 Exchange Server security update permanently disables the OWA Light client across all servers. This update addresses an authentication-bypass vulnerability demonstrated at Pwn2Own, affecting Exchange Server 2016 and 2019. Organizations must be enrolled in Period 2 Extended Security Updates to continue receiving updates. Additionally, the update exposes a hybrid-deployment issue impacting messages from shared mailboxes, requiring administrators to conduct post-update checks. The vulnerabilities could potentially allow unauthorized access to sensitive information if not addressed. The update is critical for maintaining security in affected systems, and organizations are urged to apply it promptly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 57d ago How this analysis works

Timeline

2026-08-12
Exchange Server August 2026 update released
Microsoft released a security update that disables OWA Light and fixes a Pwn2Own vulnerability affecting Exchange Server 2016 and 2019.
Feeds.4Sysops
2026-08-12
Hybrid mailbox bug identified
The update also exposes a hybrid-deployment issue affecting messages from shared mailboxes, necessitating checks by administrators.
Feeds.4Sysops

More articles in this cluster (2)