01303 883111 info@meridian-micro.com Support Login
meridianmicro
Get in Touch
01303 883111 info@meridian-micro.com
IT Support

Exchange Server August 2026 Update Breaks Anonymous Calendar Subscriptions: What Kent SMEs Must Fix Now

August 27, 2026 Meridian Micro
Moodle Server

Microsoft released its August 2026 Exchange Server security updates on 25 August, and whilst the patch addresses important vulnerabilities,
it has introduced a critical known issue: subscriptions to anonymously published Exchange calendars stop refreshing after installation, with the subscribing application reporting a server error and the URL returning HTTP 500
. For Kent SMEs running on-premises Exchange Server who share calendars with external partners, suppliers or customers, this is a business-critical problem that demands immediate attention.

This is separate from the earlier August 2026 Patch Tuesday Exchange updates released on 11 August, and affects organisations that applied Microsoft’s most recent security rollout at the end of the month.

What the Exchange Server August 2026 Security Update Changes

The latest update includes important security fixes, but
it permanently disables the OWA Light client when installed on an Exchange server, as detailed in CVE-2026-62914, and customers who cannot install the August 2026 or later update should disable OWA Light manually to address this particular CVE
.

For organisations still running legacy versions,
Exchange Server 2016 and 2019 are out of support, with only customers who enrolled in the Period 2 Extended Security Update (ESU) programme eligible to receive security updates released between May and October 2026, and those not in the ESU programme must migrate to Exchange Server Subscription Edition to keep receiving security updates
.

The Anonymous Calendar Subscription Problem Explained

Many UK SMEs use Exchange Server’s ability to publish calendars anonymously so external contacts can subscribe to availability, room bookings, or event schedules without needing credentials. This is common in sectors such as legal, accountancy, property and professional services where appointments, availability or resource booking must be visible to clients and partners.

After the 25 August update, these calendar URLs fail with HTTP 500 server errors, breaking external integrations and causing scheduling chaos. The subscribing application—whether Outlook, a mobile calendar app, or scheduling software—receives an error instead of updated calendar data.

Who Is Affected?

Additional Known Issues in the August 2026 Exchange Update

The calendar issue is not the only problem.
If a backend mailbox server is updated to the August 2026 SU but the frontend server proxying the inbound MRS connection is on an older version, MRS migration might fail with TooManyTransientFailureRetriesPermanentException error, which can manifest on any MRS request including Test-MigrationServerAvailability
. This affects businesses mid-migration or running split-version Exchange environments.

What Kent SMEs Must Do Now

1. Identify Whether You Are Affected

Check whether your organisation uses anonymous calendar publishing. Review email signatures, websites, and partner documentation for calendar subscription URLs. Test any published calendars externally to confirm they still refresh correctly.

2. Monitor Microsoft’s Guidance Closely

Microsoft has acknowledged the calendar issue in its official release notes. At the time of publication, a fix is expected in a future update, but no timeline has been confirmed. Do not assume the issue will resolve itself—proactive monitoring is essential.

3. Consider Temporary Workarounds

For critical external calendar sharing, temporary alternatives may include:

4. Review Your Patching Strategy for Multi-Server Environments

If you run multiple Exchange servers, ensure frontend and backend servers are updated in sync to avoid MRS migration errors. Staggered patching schedules can introduce version mismatches that break mailbox moves and migrations.

5. Align with Microsoft’s 3-Day Patching Window

Microsoft’s broader patching guidance remains in force. As covered in our recent article on why UK SMEs can no longer delay patching in 2026,
Microsoft warns that delaying critical quality updates for weeks gives attackers using AI ample time to find and exploit known security gaps, and the company has updated its recommendations to deploy Windows updates within less than three days with deadlines set to zero or one day and a maximum update grace period of two days
.

The same principle applies to Exchange Server: patch promptly, but test and monitor for known issues, especially in production environments with external dependencies.

Why On-Premises Exchange Server Management Remains Complex in 2026

This incident underscores the growing complexity of maintaining on-premises Exchange Server. Microsoft’s focus has shifted heavily toward cloud-first solutions, and organisations running Exchange Server 2016 or 2019 face mounting pressure to migrate or enrol in expensive ESU programmes.

At the same time, patch volumes continue to rise. The August 2026 Patch Tuesday release fixed 421 vulnerabilities, part of a broader trend driven by AI-powered vulnerability discovery. For SMEs without dedicated IT teams, keeping pace with patching whilst avoiding service-breaking known issues requires specialist support.

How Meridian Micro Supports Kent SMEs with Exchange Server Management

Managing Exchange Server securely and reliably means balancing rapid security patching with operational stability. Our team monitors Microsoft release notes, tests updates in controlled environments, and schedules deployments to minimise business disruption.

We help Kent and South East businesses:

If your organisation runs Exchange Server on-premises and you’re experiencing calendar errors, migration issues, or uncertainty about patching strategy, call us today on 01303 883111. We’ll assess your environment, identify affected services, and implement a fix that keeps your email and calendaring infrastructure secure and functional.