Australia’s cyber agency is warning that attackers are exploiting two N-able N-central authentication bypass flaws locally. For MSPs and enterprise IT teams, a trusted management console can become a route across hundreds of customer endpoints.
A month after the Hugging Face breach, new details reveal AI agents coordinated, rebuilt deleted infrastructure and escalated access in hours. The fallout is now reaching Congress, regulators and frontier labs, raising urgent questions about AI security and control.
A Zhuhai operator used DeepSeek, a Hermes agent and a godmode jailbreak to hunt 460-plus targets. Open-weight models made the offensive kit a shopping list.
19th May 2026 Cyber Update: Exchange Zero-Day Puts On-Prem Mail Servers Back in the Spotlight
Microsoft has confirmed active exploitation of CVE-2026-42897, putting exposed on-prem Exchange and Outlook Web Access environments back under pressure.
Microsoft Exchange is again in focus for enterprise patching after Microsoft confirmed exploitation of CVE-2026-42897, a vulnerability affecting Outlook Web Access in on‑premises Exchange Server deployments. The issue does not affect Exchange Online, an important distinction for boards and technology teams before the discussion becomes too broad.
The Update
CVE-2026-42897 affects Exchange Server 2016, Exchange Server 2019 and Exchange Server Subscription Edition. Microsoft says an attacker could send a specially crafted email and, if the user opens it in Outlook Web Access under certain conditions, arbitrary JavaScript can run in the browser context. The US Cybersecurity and Infrastructure Security Agency has added the flaw to its Known Exploited Vulnerabilities catalogue, giving US federal agencies until 29 May 2026 to apply mitigations.
The immediate control is not a full patch. Microsoft is using the Exchange Emergency Mitigation Service to apply protection automatically where that service is enabled. For disconnected environments, Microsoft has provided a scripted mitigation path. A permanent security update is still pending, and Microsoft has warned that some older or unsupported Exchange positions may face limits around future fixes.
Why It Matters
Exchange remains one of those systems that many organisations keep running because business workflows, legacy mailboxes and hybrid identity arrangements make removal harder than the strategy slide suggests. That is why cyber observers keep returning to the same point: exposed on-prem mail infrastructure can become a high-value doorway into the organisation, even when most users have already moved to cloud services.
The market read is practical rather than dramatic. Security teams should confirm whether they still operate any on-prem Exchange server, check whether the Exchange Emergency Mitigation Service is enabled, validate that mitigation status, and review whether Outlook Web Access is unnecessarily exposed. Multiple cyber media outlets note that Microsoft’s mitigation may create some usability issues, including calendar printing and inline image display problems, but those trade-offs are easier to manage than an exploited mail server.
The question that needs answering is about operational discipline: do organisations have a clean inventory of legacy internet-facing systems, and can they apply emergency controls quickly when a widely targeted platform enters the exploited-vulnerability list?
For boards and executive teams, the message is clear. Ask for confirmation, not reassurance. Which Exchange servers exist? Which are exposed? Which have the emergency mitigation applied? Which business owner accepts the risk if unsupported versions remain online?
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Australia’s cyber agency is warning that attackers are exploiting two N-able N-central authentication bypass flaws locally. For MSPs and enterprise IT teams, a trusted management console can become a route across hundreds of customer endpoints.
A record close on Wall Street and the AI names that were meant to lead it taken apart in the same session. Beijing is now drafting export controls on its own models. The labs keep finding their systems outside the box. Read one at a time, it is a normal week. Read together, something else entirely.
As artificial intelligence automates both attack and defence, the window to patch critical vulnerabilities is vanishing. Black Hat 2026 research confirms autonomous systems are discovering thousands of previously unreported flaws.
Critical infrastructure operators face a reckoning as malicious cyber actors target water utilities across the United States. Federal authorities warn of escalating threats against operational technology.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!