Feeds.4Sysops
Exchange Server August 2026 Update Disables OWA Light and Addresses Vulnerabilities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Microsoft's August 2026 Exchange Server security update permanently disables the OWA Light client across all servers. This update addresses an authentication-bypass vulnerability demonstrated at Pwn2Own, affecting Exchange Server 2016 and 2019. Organizations must be enrolled in Period 2 Extended Security Updates to continue receiving updates. Additionally, the update exposes a hybrid-deployment issue impacting messages from shared mailboxes, requiring administrators to conduct post-update checks. The vulnerabilities could potentially allow unauthorized access to sensitive information if not addressed. The update is critical for maintaining security in affected systems, and organizations are urged to apply it promptly.
Key Points: • The August 2026 update disables OWA Light and addresses a critical authentication bypass. • Only organizations enrolled in Extended Security Updates for Exchange Server 2016 and 2019 will receive updates. • A hybrid-deployment issue affecting shared mailboxes requires administrators' attention post-update.