Microsoft releases August security updates for Exchange Server and disables OWA Light

Microsoft releases August security updates for Exchange Server and disables OWA Light

Microsoft's August 2026 Exchange Server security updates disable OWA Light and limit older server fixes to ESU customers.

Format News Brief
Read Time 2 min
Category Cyber Security
Updated Aug 12, 2026

Microsoft has shipped its August 2026 security updates for on-premises Exchange Server, giving administrators another urgent maintenance window for mail infrastructure that remains inside their own environments. The Exchange Team said the release covers Exchange Server Subscription Edition, Exchange Server 2019 and Exchange Server 2016, with the older 2016 and 2019 builds available only to customers enrolled in Microsoft's Period 2 Extended Security Update program.

The most visible product change is that Outlook Web App Light is permanently disabled once this update, or a later Exchange update, is installed. Microsoft tied that change to CVE-2026-62914 and advised organizations that cannot install the August update to disable OWA Light on their servers as a mitigation. That makes the release more than a routine patch bundle: it removes a legacy web client path that some organizations may still depend on for low-bandwidth or older-browser scenarios.

Who needs to act

Exchange Online customers are already protected for the vulnerabilities addressed by the release, according to Microsoft, but hybrid organizations still need to update any on-premises Exchange servers and Exchange Management tools workstations they operate. For self-managed Exchange, Microsoft recommends inventorying servers, installing the latest cumulative update where required, applying the security update, and rerunning its Health Checker script afterward to confirm whether more action is needed.

The update lands during a large August Patch Tuesday. Rapid7's analysis says Microsoft published 421 vulnerabilities for the month, including 236 affecting Windows, and noted one vulnerability with exploitation in the wild plus two public disclosures. Those totals do not make every organization equally exposed, but they raise the value of disciplined asset inventory and prioritization, especially for internet-facing collaboration systems such as Exchange and SharePoint.

For administrators, the immediate takeaway is practical: confirm which Exchange versions are still present, verify ESU eligibility for Exchange 2016 or 2019 if those servers remain in service, and plan for OWA Light removal before applying the update. Organizations that are not in the ESU program are being pointed toward Exchange Server Subscription Edition if they want to continue receiving security updates.

Sources

Cover photo by Brett Sayles on Pexels, used under the Pexels License.

Comments (0)

Leave a Comment

Loading comments...