Security9 min read

When Print Servers and Edge Gateways Are Open: A September 2026 UK SME Threat Briefing

Late August and early September 2026 put internet-facing edge kit back at the top of the list. PaperCut print servers are under active pre-auth exploitation, SonicWall SMA1000 remote-access appliances have a CVSS 10 chain in the wild and the NCSC warned that disruptive activity against exposed systems and edge devices is rising. A practical briefing for UK SMEs.

Nimbul Systems Team
8 September 2026
9 min read

The fortnight spanning late August and early September 2026 has a clear theme for UK SMEs: things you put on the internet because they are "just infrastructure" are being treated as primary targets. Three items belong on this month's list. PaperCut NG/MF Application Servers are under confirmed pre-authentication remote code execution with a second wave of attacks on unpatched public hosts. SonicWall SMA1000 secure remote-access appliances have a CVSS 10.0 SSRF chained with command injection and confirmed exploitation before disclosure. The NCSC's 27 August alert on disruptive cyber activity against internet-exposed systems and edge devices is the frame that ties both together.

This is a briefing. Skip to the sections that apply to your stack.

1. PaperCut NG/MF: three emergency patches in five days

On 27 August 2026 PaperCut published an URGENT Security Advisory stating it was investigating active exploitation of a vulnerability in PaperCut NG and PaperCut MF, with confirmed customer incidents. By 28 August it had shipped Emergency Patch Release 1 then Release 2 (extra hardening after work with Huntress and watchTowr, who found bypasses of the first fix). On 1 September it shipped Emergency Patch Release 3, which supersedes the earlier emergency builds and adds further hardening. On 31 August CISA added both CVEs to the Known Exploited Vulnerabilities catalog.

The chain

  • CVE-2026-81578 (CVSS 8.8): missing authentication for a critical function in the web management interface. An unauthenticated remote request can modify certain system configurations.
  • CVE-2026-82078 (CVSS 9.4): unsafe dynamic class loading in the database connection utilities. If configuration can be manipulated, arbitrary Java bytecode on the application classpath runs as the PaperCut server process.
  • Chained: pre-authentication remote code execution on the Application Server.
  • PaperCut treats all NG and MF versions as potentially affected. Hive and Pocket are not in scope. Mobility Print and Print Deploy server components are not affected. Site Servers and secondary print servers do need the patched builds, not only the primary Application Server.

    Patch to Emergency Patch Release 3 (do not stay on Release 1 or 2)

  • PaperCut NG/MF v24, v25 and v26: install Release 3 from the PaperCut bulletin. You do not need to install earlier emergency patches first. Release 3 is cumulative.
  • v23 and earlier: no emergency patch on that line. Upgrade to a supported major version then apply Release 3.
  • Confirm About / build numbers against the bulletin after install. If you applied only the first or second emergency build, treat the server as still needing Release 3.
  • Containment that cannot wait for a change window

    If the Application Server web UI is reachable from the public internet, restrict it to trusted IP addresses now (firewall or network ACL). PaperCut's first-line advice is to remove untrusted internet reachability even before you patch. A print-management console does not need a public IP.

    Hunt if it was internet-reachable while unpatched

    Preserve evidence before an upgrade overwrites it. Then look for:

  • Missing, truncated or deleted 'server.log' files.
  • Log strings such as 'ERROR No suitable driver found for jdbc:no:x' or 'DB URL: jdbc:derby:memory:pwn;create=true' or 'Database error looking up cardID: VALUES CAST'.
  • Unexpected '.class' files under 'server/lib/' and matching '.cmd' or '.out' files under 'server/data/content/' (often five-character names; absence does not clear the host).
  • 'pc-app.exe' (or 'pc-app') spawning shells or discovery commands such as 'whoami', 'ver' and 'tasklist'.
  • Post-compromise tooling PaperCut has flagged in the field: a Windows service named 'Remote Access Service' running 'SimpleService.exe' from a JWrapper/SimpleHelp path under 'C:\ProgramData\'. Also look for unexpected AnyDesk installs under 'C:\ProgramData\'.
  • PaperCut has also reported a second wave of attacks against servers that remain public and not fully patched, with more sophisticated post-compromise behaviour than the first days of the incident. If you find compromise indicators, rebuild the Application Server from a clean backup taken before suspicious activity. Credential rotation alone is not enough.

    2. SonicWall SMA1000: CVSS 10.0 and exploited before the advisory

    On 1 September 2026 SonicWall published SNWLID-2026-0016 covering two flaws in SMA 1000 Series secure mobile access appliances (models 6210, 7210 and 8200v, physical and virtual). SonicWall states both issues are confirmed as actively exploited in the wild. CISA added them to KEV on 2 September.

    The chain

  • CVE-2026-83548 (CVSS 10.0): pre-authentication server-side request forgery in the Appliance Work Place interface via an unintended forward-proxy path. Unauthenticated remote access to sensitive functionality.
  • CVE-2026-83549 (CVSS 7.8): post-authentication OS command injection in the Appliance Management Console. On its own it needs an authenticated administrator. Chained with the SSRF, reporting assesses a path to unauthenticated remote code execution.
  • Affected / fixed platform-hotfix versions

  • Affected: 12.4.3-03453 and earlier on the 12.4.3 branch; 12.5.0-02835 and earlier on the 12.5.0 branch.
  • Fixed: 12.4.3-03526 or later; 12.5.0-02952 or later (from mysonicwall.com).
  • SonicWall states these flaws are unrelated to other SonicWall product lines. SSL-VPN on SonicWall firewalls and the SMA100 series are outside this advisory. That does not excuse a delayed inventory: confirm you are not running SMA1000 under another label in a colo or MSP rack.

    Because exploitation predates public disclosure, patching is not proof of cleanliness. SonicWall's required follow-through:

  • Upgrade to the fixed platform-hotfix.
  • Contact SonicWall Technical Support for an IOC review (public IOC lists were not published with the initial notice).
  • If compromise is indicated: re-image hardware or re-deploy virtual appliances, change all user and administrator passwords and reset TOTP tokens.
  • Restrict AMC administration to a trusted management network so the post-auth half of the chain is harder to reach even if a future SSRF appears.

    3. NCSC: disruptive activity against exposed systems and edge devices

    On 27 August 2026 the NCSC published an alert: increased targeting of operational technology globally (including the UK), with limited real-world disruption so far and a wider pattern of disruptive cyber activity against internet-exposed systems and edge devices across all sectors.

    You do not need a factory floor for this to matter. The NCSC's explicit message for non-OT organisations is to maintain visibility of internet-facing assets and edge network devices. Practical actions it lists include an accurate inventory, understanding what each edge device does and what data it carries, applying vendor updates promptly, retiring end-of-life kit and disabling insecure management protocols such as SNMP v1, SNMP v2 and Telnet. Monitor for unexpected configuration changes or outbound connections.

    That is the same checklist that would have reduced exposure to both PaperCut and SMA1000 this month. The NCSC also points organisations to Early Warning, Cyber Essentials as a minimum baseline where the Cyber Assessment Framework is not appropriate and guidance on preparing for severe cyber threats and disruption.

    If you do run OT (building management, warehouse automation, light industrial controls), treat the full OT action list seriously: definitive asset view, no direct internet exposure of PLCs or HMIs, MFA and unique credentials, supported boundary devices managed from a segregated non-internet management network, protocol hardening, logging, write-protection of controller logic, segmentation and ransomware-resistant tested backups.

    The pattern behind September

  • PaperCut: a print server many SMEs treat as plumbing, internet-reachable for convenience, exploited as pre-auth RCE with confirmed customer incidents and a second attack wave on unpatched hosts.
  • SMA1000: a remote-access edge appliance exploited before the vendor advisory, requiring hotfix plus compromise review rather than "patch and assume clean".
  • NCSC: the same message as July's Fortinet and August's vCenter briefings, now stated as a national alert. Edge and internet-exposed kit is the opportunistic surface.
  • None of these needed a novel technique aimed at your line of business. They needed a public management interface, a deferred emergency patch or an appliance left on last month's hotfix. The window between vendor disclosure and mass exploitation remains measured in days and the KEV list is still the most reliable urgency signal.

    What UK SMEs should do this month

    Pick the items relevant to your stack and put a date next to each:

  • PaperCut NG/MF: Confirm every Application Server and Site Server build. Install Emergency Patch Release 3. Take the web UI off the public internet. Hunt the IoCs above if it was exposed unpatched. Rebuild if compromised.
  • SonicWall SMA1000: Confirm model and platform-hotfix. Upgrade to 12.4.3-03526 or 12.5.0-02952 (or later). Engage SonicWall support for IOC review. Re-image and rotate credentials/TOTP if indicated.
  • Internet-facing inventory: One spreadsheet. Every appliance, print server, VPN/remote-access gateway and management UI, its owner and last patch date. Anything without an owner gets unpublished this week.
  • Edge hygiene: Disable Telnet and SNMP v1/v2 on management paths. Retire end-of-life edge kit. Restrict management to jump hosts or a management VLAN.
  • Governance: Subscribe to CISA KEV and NCSC Early Warning. Treat a KEV add as your patch trigger. Cyber Essentials remains the minimum baseline.
  • MSP challenge: If a partner owns print or remote-access kit, ask today which PaperCut build and which SMA1000 hotfix you are on, whether either was internet-reachable in the last fortnight and what hunt or rebuild has been done.
  • How fractional teams help

    We inventory what is actually internet-reachable, patch PaperCut to Release 3 and SMA1000 to the fixed hotfixes, hunt the published indicators, take management interfaces off public IP space and put a KEV-triggered patch rhythm into monthly operations so an edge flaw disclosed at the end of one week is not your incident at the start of the next. If your MSP owns the kit, we help you ask the right questions and validate the answers.

    Further reading

  • PaperCut URGENT Security Advisory (27 Aug 2026 bulletin, Emergency Patch Release 3): https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
  • Huntress, PaperCut actively exploited (pre-auth RCE chain): https://www.huntress.com/blog/papercut-actively-exploited
  • CISA, PaperCut KEV additions (CVE-2026-81578 and CVE-2026-82078): https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog
  • SonicWall SNWLID-2026-0016 (SMA1000 CVE-2026-83548 and CVE-2026-83549): https://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities-snwlid-2026-0016/kA1VN000002AXmQ0AW
  • Rapid7, SonicWall SMA1000 exploitation note: https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild/
  • CISA, SonicWall and related KEV additions (2 Sep 2026): https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog
  • NCSC, Disruptive cyber activity and internet-exposed systems/edge devices (27 Aug 2026): https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-internet-exposed-systems-and-edge-devices
  • CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • NCSC Early Warning service: https://www.ncsc.gov.uk/information/early-warning-service
  • Topics Covered

    PaperCutSonicWallEdge DevicesVulnerability ManagementNCSCUK SME

    Ready to Transform Your IT Operations?

    Get expert guidance from our fractional IT specialists. We'll help you implement the strategies discussed in this article and accelerate your digital transformation journey.

    About the Author

    NS

    Nimbul Systems Team

    Our experienced team of fractional IT specialists brings over 35 years of combined expertise in DevOps automation, cloud engineering and digital transformation.

    Continue Reading

    DevOps Automation: The Complete Guide for UK SMEs

    Discover practical strategies and tools that UK SMEs can implement to accelerate development.

    Read Article →

    Cloud Migration Strategy: A UK Business Guide

    Navigate cloud migration complexity with this practical guide.

    Read Article →