Microsoft releases August security patches for Exchange Server and disables Outlook Web App Light

Microsoft has rolled out critical security fixes for Exchange Server and announced the permanent shutdown of Outlook Web App Light, urging administrators to promptly apply updates amidst ongoing bug fixes.

Microsoft has released its August security fixes for Exchange Server, alongside the usual monthly updates for Windows 11 and Windows 10, according to its official blog. The Exchange patches cover Exchange Server Subscription Edition, Exchange Server 2019 and Exchange Server 2016, although access to the latter two is limited to organisations that bought Extended Security Updates, which Microsoft says will provide support through October 2026.

The update also brings a permanent change to the product: Outlook Web App Light has now been switched off. Microsoft had signalled the retirement of the stripped-down webmail interface two years ago and repeated the warning last month. The feature, launched nearly 20 years ago, was designed for older browsers and slower connections. Administrators who cannot apply the patch immediately are being advised to disable OWA Light manually to reduce exposure on corporate mail servers.

Microsoft says the August package addresses multiple security flaws in Exchange, with particular attention to spoofing and privilege-escalation issues. The company has also acknowledged that a hybrid-mailbox bug first documented in June remains unresolved. In that case, a shared mailbox hosted in Exchange Online can generate an unexpected wrapper message in the inbox when a user with Send As or Send on Behalf rights sends mail from a local Exchange deployment and message-copy settings are enabled.

The defect affects mixed environments using Exchange Server Subscription Edition, 2019 or 2016. Microsoft says it is working on a fix and expects to deliver it in a future platform update. In the meantime, the company is pushing administrators to stay current with the latest security releases, especially as older Exchange interfaces and legacy deployment patterns are phased out.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.