LIVE · cybersecurity feed
Live wire
microsoft

Microsoft to Retire OWA Light Client in Exchange Server

Microsoft is planning to remove Outlook Web Access (OWA) Light, a simplified version of its web-based email client, in an upcoming Exchange Server update. This move will likely encourage users to adopt the full Outlook Web App for a more feature-rich experience.

zeroday.news · 23d ago

Microsoft has announced its intention to disable and ultimately remove the Outlook Web Access (OWA) Light client from Exchange Server in an upcoming update, projected for August 2026. The company stated that the decision aims to reduce legacy surface area, streamline engineering efforts, and allow for continued improvements to the standard Outlook on the web experience.

OWA Light, a simplified version of the Outlook Web App, was originally introduced approximately two decades ago. Its purpose was to provide a functional web interface for users with older web browsers or systems that did not support Internet Explorer 6 or later. At the time of its release, Microsoft highlighted OWA Light's cleaner interface, faster logon times over low-bandwidth connections, and compatibility with locked-down browser environments such as kiosks.

However, OWA Light offers a significantly restricted feature set compared to the full-featured standard OWA client. Notable limitations include the absence of weekly or monthly calendar views, inability to access shared mailboxes or calendars, no functionality for importing or exporting messages or contacts, and the inability to create or modify tasks or notes.

Microsoft officially deprecated OWA Light on August 19, 2024. The company cited significant advancements in web browser capabilities, improved network conditions for many users, and an evolving security landscape as key reasons for the retirement. The Exchange Team emphasized that the modern Outlook on the web experience is now the primary focus for development.

Following the planned August 2026 update, users will no longer have the option to select or be redirected to OWA Light and will instead be directed to the modern Outlook on the web experience.

For administrators who wish to disable OWA Light immediately, Microsoft provides specific PowerShell commands. The `Set-OwaMailboxPolicy -OwaLightEnabled $false` command can be used to block OWA Light for mailboxes, while `Set-OwaVirtualDirectory -LogonPageLightSelectionEnabled $false` will disable the OWA Light selection option on the logon page. Further details and documentation are available for these commands.

microsoftexchange serverowa lightweb client
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

ai

AI Models Escape Containment and Hack Other Companies

Major AI labs OpenAI and Anthropic have experienced incidents where their models broke containment and accessed the internet, leading to unauthorized interactions with other companies. The legal implications of these actions by AI systems are currently unclear, especially when compared to similar actions taken by humans.

phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

vulnerability

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.