Summary: The August 2026 Exchange Server security update removes OWA Light for good. If you can’t install the update yet, disable OWA Light manually now, it’s tied to a CVE.
The Change, in Brief
On August 11, 2026, Microsoft released Security Updates (SUs) for:
- Exchange Server Subscription Edition (SE) — RTM
- Exchange Server 2019 — CU14/CU15 (Period 2 ESU only)
- Exchange Server 2016 — CU23 (Period 2 ESU only)
Installing this update, or any later one, permanently disables the OWA Light client. This is a deliberate fix, it’s addressing a specific vulnerability, CVE-2026-62914.
Exchange Online is unaffected, this is an on-premises Exchange Server issue only.
Microsoft’s Justification
Microsoft first announced the deprecation back in August 2024, then confirmed the retirement timeline on July 8, 2026. The stated reasoning:
- OWA Light was built for old browsers and slow connections that no longer represent typical usage.
- Every legacy rendering path is extra attack surface. Removing it simplifies Exchange’s security posture.
The July 8 post was updated on August 13, 2026 confirming the retirement is complete as of the August SU.
If you can’t install the August update yet
Microsoft’s guidance: disable OWA Light manually to close the CVE, even if you’re not ready to patch.
# Block OWA Light via mailbox policy Set-OwaMailboxPolicy -OwaLightEnabled $false # Make sure the policy is actually assigned Set-CasMailbox -OwaMailboxPolicy <PolicyName> # Remove the OWA Light option from the logon page Set-OwaVirtualDirectory -LogonPageLightSelectionEnabled $false
Patching eligibility 2016 / 2019
Exchange Server 2016 and 2019 are out of support. You only get this SU if you’re enrolled in the Period 2 Extended Security Update (ESU) program, which covers releases from May–October 2026.
- Not enrolled? → Migrate to Exchange Server SE to keep getting security updates.
Known issue in this release
A bug present since June 2026 persists in this update. It hits hybrid environments where:
- A shared mailbox lives in Exchange Online
- A mailbox on-prem has Send As / Send on Behalf rights to it
- MessageCopyForSentAsEnabled or MessageCopyForSendOnBehalfEnabled is turned on
Symptom: messages sent as/on behalf of the shared mailbox get delivered back into the shared mailbox’s own inbox, wrapped as an attachment. No fix yet, Microsoft says it’s coming in a future release.
Fortify Your Server with Messageware Security
Data breaches have increased by 72%, servers are compromised in under 90 minutes. Ensure you have multiple layers of security software protecting your Windows Servers.
Server Threat Guard (STG) for All Windows Servers: Next-gen server protection, providing detection, alerting, and response (MDR) to zero-day and server penetration cyber-attacks. No need to research complicated deployments and no learning curve to install and manage.
EPG Guard for Exchange Servers: Real-time security. Stop AD account lockouts, eliminate password attacks, intelligent GEO blocking, and prevent Exchange Server vulnerability probing.
Don’t leave your critical infrastructure vulnerable, be proactive and stay ahead of evolving threats.