When Print Servers and Edge Gateways Are Open: A September 2026 UK SME Threat Briefing
Late August and early September 2026 put internet-facing edge kit back at the top of the list. PaperCut print servers are under active pre-auth exploitation, SonicWall SMA1000 remote-access appliances have a CVSS 10 chain in the wild and the NCSC warned that disruptive activity against exposed systems and edge devices is rising. A practical briefing for UK SMEs.
The fortnight spanning late August and early September 2026 has a clear theme for UK SMEs: things you put on the internet because they are "just infrastructure" are being treated as primary targets. Three items belong on this month's list. PaperCut NG/MF Application Servers are under confirmed pre-authentication remote code execution with a second wave of attacks on unpatched public hosts. SonicWall SMA1000 secure remote-access appliances have a CVSS 10.0 SSRF chained with command injection and confirmed exploitation before disclosure. The NCSC's 27 August alert on disruptive cyber activity against internet-exposed systems and edge devices is the frame that ties both together.
This is a briefing. Skip to the sections that apply to your stack.
1. PaperCut NG/MF: three emergency patches in five days
On 27 August 2026 PaperCut published an URGENT Security Advisory stating it was investigating active exploitation of a vulnerability in PaperCut NG and PaperCut MF, with confirmed customer incidents. By 28 August it had shipped Emergency Patch Release 1 then Release 2 (extra hardening after work with Huntress and watchTowr, who found bypasses of the first fix). On 1 September it shipped Emergency Patch Release 3, which supersedes the earlier emergency builds and adds further hardening. On 31 August CISA added both CVEs to the Known Exploited Vulnerabilities catalog.
The chain
PaperCut treats all NG and MF versions as potentially affected. Hive and Pocket are not in scope. Mobility Print and Print Deploy server components are not affected. Site Servers and secondary print servers do need the patched builds, not only the primary Application Server.
Patch to Emergency Patch Release 3 (do not stay on Release 1 or 2)
Containment that cannot wait for a change window
If the Application Server web UI is reachable from the public internet, restrict it to trusted IP addresses now (firewall or network ACL). PaperCut's first-line advice is to remove untrusted internet reachability even before you patch. A print-management console does not need a public IP.
Hunt if it was internet-reachable while unpatched
Preserve evidence before an upgrade overwrites it. Then look for:
PaperCut has also reported a second wave of attacks against servers that remain public and not fully patched, with more sophisticated post-compromise behaviour than the first days of the incident. If you find compromise indicators, rebuild the Application Server from a clean backup taken before suspicious activity. Credential rotation alone is not enough.
2. SonicWall SMA1000: CVSS 10.0 and exploited before the advisory
On 1 September 2026 SonicWall published SNWLID-2026-0016 covering two flaws in SMA 1000 Series secure mobile access appliances (models 6210, 7210 and 8200v, physical and virtual). SonicWall states both issues are confirmed as actively exploited in the wild. CISA added them to KEV on 2 September.
The chain
Affected / fixed platform-hotfix versions
SonicWall states these flaws are unrelated to other SonicWall product lines. SSL-VPN on SonicWall firewalls and the SMA100 series are outside this advisory. That does not excuse a delayed inventory: confirm you are not running SMA1000 under another label in a colo or MSP rack.
Because exploitation predates public disclosure, patching is not proof of cleanliness. SonicWall's required follow-through:
Restrict AMC administration to a trusted management network so the post-auth half of the chain is harder to reach even if a future SSRF appears.
3. NCSC: disruptive activity against exposed systems and edge devices
On 27 August 2026 the NCSC published an alert: increased targeting of operational technology globally (including the UK), with limited real-world disruption so far and a wider pattern of disruptive cyber activity against internet-exposed systems and edge devices across all sectors.
You do not need a factory floor for this to matter. The NCSC's explicit message for non-OT organisations is to maintain visibility of internet-facing assets and edge network devices. Practical actions it lists include an accurate inventory, understanding what each edge device does and what data it carries, applying vendor updates promptly, retiring end-of-life kit and disabling insecure management protocols such as SNMP v1, SNMP v2 and Telnet. Monitor for unexpected configuration changes or outbound connections.
That is the same checklist that would have reduced exposure to both PaperCut and SMA1000 this month. The NCSC also points organisations to Early Warning, Cyber Essentials as a minimum baseline where the Cyber Assessment Framework is not appropriate and guidance on preparing for severe cyber threats and disruption.
If you do run OT (building management, warehouse automation, light industrial controls), treat the full OT action list seriously: definitive asset view, no direct internet exposure of PLCs or HMIs, MFA and unique credentials, supported boundary devices managed from a segregated non-internet management network, protocol hardening, logging, write-protection of controller logic, segmentation and ransomware-resistant tested backups.
The pattern behind September
None of these needed a novel technique aimed at your line of business. They needed a public management interface, a deferred emergency patch or an appliance left on last month's hotfix. The window between vendor disclosure and mass exploitation remains measured in days and the KEV list is still the most reliable urgency signal.
What UK SMEs should do this month
Pick the items relevant to your stack and put a date next to each:
How fractional teams help
We inventory what is actually internet-reachable, patch PaperCut to Release 3 and SMA1000 to the fixed hotfixes, hunt the published indicators, take management interfaces off public IP space and put a KEV-triggered patch rhythm into monthly operations so an edge flaw disclosed at the end of one week is not your incident at the start of the next. If your MSP owns the kit, we help you ask the right questions and validate the answers.
Further reading
Topics Covered
Ready to Transform Your IT Operations?
Get expert guidance from our fractional IT specialists. We'll help you implement the strategies discussed in this article and accelerate your digital transformation journey.
About the Author
Nimbul Systems Team
Our experienced team of fractional IT specialists brings over 35 years of combined expertise in DevOps automation, cloud engineering and digital transformation.
Continue Reading
DevOps Automation: The Complete Guide for UK SMEs
Discover practical strategies and tools that UK SMEs can implement to accelerate development.
Read Article →Cloud Migration Strategy: A UK Business Guide
Navigate cloud migration complexity with this practical guide.
Read Article →