If you run Exchange Server SE, 2019 or 2016, or the installed (MSI) edition of Outlook 2016, install Microsoft's August 11, 2026 security updates; for Exchange 2016 and 2019, they're for Extended Security Update customers. The Exchange updates fix seven vulnerabilities and permanently switch off OWA Light. The Outlook update fixes a spoofing flaw and two code-execution flaws.
Key takeaways
- On August 11, 2026, Microsoft released security updates for Exchange Server SE RTM, Exchange Server 2019 CU14 and CU15, and Exchange Server 2016 CU23. Each lists the same seven CVEs.
- Installing the August Exchange update permanently disables OWA Light, which addresses CVE-2026-62914. If you can't install it yet, Microsoft says to disable OWA Light yourself.
- Outlook 2016 update KB5002755 fixes an Outlook spoofing vulnerability, an Outlook remote code execution vulnerability and a Word remote code execution vulnerability.
- Microsoft says Exchange 2016 and 2019 have reached end of support. Organizations in its Period 2 Extended Security Update (ESU) program are eligible to receive released security updates until the end of October 2026.
- Patching protects your mail server and apps. SPF, DKIM and DMARC help stop criminals forging your domain name. You need both.
What happened?
On Tuesday, August 11, 2026, Microsoft shipped its monthly security updates, including fixes for on-premises Exchange Server and Outlook 2016.
Exchange Server: seven fixes and the end of OWA Light
Microsoft's Exchange team says the August security updates cover Exchange Server Subscription Edition (SE), Exchange Server 2019 and Exchange Server 2016, and address vulnerabilities reported by security partners or found through Microsoft's internal processes. Each update's support article lists the same seven CVEs: CVE-2026-62910, CVE-2026-62911, CVE-2026-62912, CVE-2026-62913, CVE-2026-62914, CVE-2026-62915 and CVE-2026-65813.
| If you run | Install (released Aug 11, 2026) | Build number after install |
|---|---|---|
| Exchange Server SE RTM | KB5121573 | 15.2.2562.46 |
| Exchange Server 2019 CU15 | KB5121574 | 15.2.1748.49 |
| Exchange Server 2019 CU14 | KB5121575 | 15.2.1544.44 |
| Exchange Server 2016 CU23 | KB5121576 | 15.1.2507.72 |
| Outlook 2016 (MSI edition) | KB5002755 | n/a |
The biggest visible change is to OWA Light, the basic version of Outlook on the web. According to Microsoft, starting with this update and any later one, OWA Light is permanently disabled when the update is installed on an Exchange server. That change addresses CVE-2026-62914. Microsoft says customers who can't install the August 2026 (or a later) update should disable OWA Light on their servers to address that CVE.
Each Exchange support article also lists known issues, including at least one that affects hybrid deployments. Read them before you schedule the install.
Exchange 2016 and 2019: past end of support
Microsoft's August 11 support articles for Exchange 2016 and 2019 say both versions have reached end of support. Organizations enrolled in the Period 2 ESU program are eligible to receive released security updates until the end of October 2026. Microsoft says organizations that aren't enrolled should migrate to Exchange Server SE to keep receiving the latest security updates.
Outlook 2016: a spoofing fix and two code-execution fixes
Microsoft's KB5002755 article says the Outlook 2016 update resolves a Microsoft Outlook spoofing vulnerability, a Microsoft Outlook remote code execution vulnerability and a Microsoft Office Word remote code execution vulnerability, listed as CVE-2026-62882, CVE-2026-70329 and CVE-2026-63518. Two practical details from Microsoft:
- You need the release version of Outlook 2016 installed to apply it.
- The Download Center package applies to the MSI-based edition of Office 2016, not to Click-to-Run editions such as Microsoft Office 365 Home.
Microsoft 365 Apps got fixes for the same three Outlook CVEs on August 11. Microsoft's Office security release notes list Current Channel Version 2607 (Build 20228.20190) for that release.
Why does this matter for your business?
Your mail server is part of your email security. An on-premises Exchange server holds every mailbox, contact list and invoice thread in the company, and if Outlook on the web is published to the internet, it's reachable from anywhere. Mail sent from your own server also comes from a source your SPF record authorizes. If an attacker controls that server, SPF, DKIM and DMARC can't tell their messages from yours. Keeping the server patched is a big part of preventing that.
"Spoofing" in a CVE name isn't the same as domain spoofing. The Outlook spoofing fix is for a flaw in the Outlook software itself, and the update is the cure. Forging your domain in the From address is a separate problem that SPF, DKIM and DMARC address (see the FAQ below).
Old software is running out of road. Exchange 2016 and 2019 depend on the paid ESU program for fixes, and Microsoft's own guidance is to move to Exchange Server SE. If you run your own mail server mainly out of habit, it's a good moment to ask whether that still makes sense. Keeping software current is also on our small business email security checklist.
What should you do now?
Find out exactly what you run. For Exchange, Microsoft recommends running the Exchange Health Checker script and reading the build number, or running this in the Exchange Management Shell:
Get-Command Exsetup.exe | ForEach-Object {$_.FileVersionInfo}For Outlook, Microsoft's "What version of Office am I using?" page explains how to tell an MSI install from Click-to-Run.
Read the known issues, then install the August update that matches your version and CU. Microsoft notes that installing an Exchange security update without elevated permissions on a server with User Account Control enabled can leave Outlook on the web or the Exchange Control Panel broken, so install it from an elevated (Run as administrator) prompt.
Run the Exchange Health Checker afterward. Microsoft's support articles recommend it to confirm the install succeeded and to flag any further actions.
Warn anyone who uses OWA Light. Once the update is installed, OWA Light is gone, so those users will need the standard Outlook on the web.
If you truly can't patch this week, disable OWA Light now. That's Microsoft's guidance for CVE-2026-62914. It doesn't address the other six CVEs, so schedule the full update as soon as you can.
Update Outlook. For MSI Outlook 2016, install KB5002755 through Microsoft Update, or use the standalone package links in Microsoft's KB5002755 article. For Microsoft 365 Apps, confirm you're on the August 11 build or later.
On Exchange 2016 or 2019 without ESU? Treat migration as urgent, whether to Exchange Server SE or to a hosted service.
Check your domain's authentication while you're at it. Our free email security scanner shows whether your SPF, DKIM and DMARC records are in place.
If you'd rather have someone review your setup, our email security services team can help, or call (818) 574-8240.
Frequently asked questions
What is OWA Light, and why did Microsoft disable it?
OWA Light is the basic version of Outlook on the web. Microsoft says installing the August 2026 Exchange update, or any later one, permanently disables it, and ties that change to CVE-2026-62914. Organizations that can't install the update yet should disable OWA Light on their servers. Users who relied on it will need to switch to the standard Outlook on the web.
We use Microsoft 365. Do these updates apply to us?
The Exchange updates are for Exchange Server, the version you install and run yourself. If all your mailboxes are in Exchange Online, there's no Exchange server for you to patch, although a hybrid setup still has one. Your Outlook apps still matter: Microsoft 365 Apps received fixes for the same three Outlook vulnerabilities on August 11.
Is the Outlook "spoofing vulnerability" the same as email spoofing?
No. It's a flaw in the Outlook software that Microsoft classifies as spoofing, and installing the update is the fix. Email spoofing in the everyday sense means forging your domain in the From address, which SPF, DKIM and an enforced DMARC policy are designed to stop. Microsoft's KB article doesn't explain how the Outlook flaw works; each CVE's entry in Microsoft's Security Update Guide has the details.
Are Exchange Server 2016 and 2019 still getting security updates?
Only for some organizations. Microsoft's August 11 support articles say both versions have reached end of support, and that organizations enrolled in the Period 2 Extended Security Update program are eligible for released security updates until the end of October 2026. Microsoft advises everyone else to migrate to Exchange Server Subscription Edition to keep receiving security updates.
Sources
- Microsoft Exchange Team Blog — Released: August 2026 Exchange Server Security Updates (August 2026)
- Microsoft Support — Description of the security update for Microsoft Exchange Server Subscription Edition RTM: August 11, 2026 (KB5121573) (August 11, 2026)
- Microsoft Support — Description of the security update for Microsoft Exchange Server 2019 CU15: August 11, 2026 (KB5121574) (August 11, 2026)
- Microsoft Support — Description of the security update for Microsoft Exchange Server 2019 CU14: August 11, 2026 (KB5121575) (August 11, 2026)
- Microsoft Support — Description of the security update for Microsoft Exchange Server 2016 CU23: August 11, 2026 (KB5121576) (August 11, 2026)
- Microsoft Support — Description of the security update for Outlook 2016: August 11, 2026 (KB5002755) (August 11, 2026)
- Microsoft Learn — Release notes for Microsoft Office security updates (August 11, 2026 entry)
- Microsoft Learn — Exchange Server build numbers and release dates (reference documentation; August 11, 2026 entries)
- Microsoft Learn — OWA or ECP stops working after you install a security update (reference documentation, undated)
- Microsoft Learn — Email authentication in cloud organizations (reference documentation, undated)
Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.
Related Topics
Ready to Secure Your Email?
Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.