Threat Analysis: CVE-2026-62911 Exchange Auth Bypass, PaperCut Zero-Days, and the Softaculous BGP Hijack, What UK SMBs Need to Know

Threats & Attacks

Threat Analysis: CVE-2026-62911 Exchange Auth Bypass, PaperCut Zero-Days, and the Softaculous BGP Hijack, What UK SMBs Need to Know

Hello, Mauven here.

This is your Daily Threat Analysis for the 1st of September 2026.

Three things confirmed active today, and all three have a direct path into UK small business environments. I am not going to bury the lead.


CVE-2026-62911: The Microsoft Exchange Authentication Bypass That 22,000 Organisations Have Not Patched

Nearly 22,000 Microsoft Exchange servers remain exposed to the internet without a patch for CVE-2026-62911, a high-severity authentication bypass vulnerability that allows an unauthenticated attacker to hijack all user mailboxes on the affected server.

Let me be precise about what “hijack all user mailboxes” means in practice. An attacker who successfully exploits this does not need credentials. They can read email, send email as any user, access calendar data, and access any files shared through Exchange. In a business context, that is your contracts, your financial correspondence, your HR communications, and, if your staff use Exchange for anything sensitive, potentially your clients’ data too.

The advisory attributes this to a high-severity rating. What it does not say loudly enough is that 22,000 servers being unpatched at this point is not a technical failure. It is an organisational one.

On-premises Exchange has been a persistent target for exactly this category of attack since at least 2021. The pattern is well established: vulnerability disclosed, patch issued, significant proportion of the installed base remains unpatched weeks or months later, exploitation follows. The NCSC has published guidance on Exchange patching practices repeatedly. The fact we are still having this conversation about 22,000 exposed servers tells you everything about how seriously patch management is being treated at the organisations running them.

Who this affects in the UK SMB context: Any organisation still running Exchange on-premises rather than having migrated to Exchange Online. This includes a substantial proportion of small professional services firms, legal practices, accountancy firms, and construction businesses that either chose not to migrate or were advised by their IT provider that on-premises was fine. If your email runs through a server in your office or a server your IT provider manages on your behalf, ask today whether it is patched.

What to do:

  • Confirm with your IT provider whether you are running on-premises Exchange or Exchange Online. If it is on-premises, ask for written confirmation that CVE-2026-62911 has been patched and when.
  • If you cannot get a straight answer, that is your answer.
  • If patching is not possible immediately, ask about interim mitigations and what monitoring is in place.

PaperCut Zero-Days: The Patch Exists, Which Means Nothing If You Have Not Applied It

Two vulnerabilities in PaperCut NG and PaperCut MF, print management software used in thousands of UK offices, were patched last week after being exploited as zero-days. They are now being used in active data theft campaigns.

This is the part of the vulnerability lifecycle that does not get enough attention. The moment a patch is released, researchers and threat actors alike begin reverse-engineering it to understand precisely what was wrong with the unpatched version. The window between patch release and widespread active exploitation has been shrinking for years. In this case, the gap was under a week.

PaperCut is genuinely widespread. It is used in education, professional services, healthcare, and retail, anywhere that centralised print management matters. If your organisation uses it and your IT provider patched it last week, good. If they have not, the fact that a patch now exists does not protect you.

The data theft angle is worth noting specifically. This is not ransomware deployment, where you find out immediately. Data theft campaigns are designed to be quiet. Attackers get in, exfiltrate what they want, and leave, or stay, depending on their objectives. You may not know for weeks or months, if you find out at all.

Who this affects: Any UK business using PaperCut NG or PaperCut MF for print management. Your IT provider or managed service provider should have an inventory of what print management software is running in your environment.

What to do:

  • Ask your IT provider to confirm PaperCut has been updated and the specific version number post-patch.
  • Ask whether there are signs of compromise prior to patching, anomalous print server activity, unusual outbound connections from the print server, unexpected configuration changes.
  • If PaperCut is internet-facing (it should not be, but some installations are), treat this as a priority incident until confirmed otherwise.

The Softaculous BGP Hijack: 33 Hours of Poisoned Hosting Infrastructure

This one requires a brief explanation of the mechanism, because “BGP hijack” is the kind of phrase that gets used and then not explained.

BGP, Border Gateway Protocol, is the routing protocol that determines how internet traffic gets from one place to another. A BGP hijack occurs when an attacker announces routes that redirect traffic intended for a legitimate destination through attacker-controlled infrastructure instead. The victim’s traffic arrives where it was going, or appears to, but it has passed through hostile hands first.

In this case, Softaculous, the software panel that manages application installations on shared hosting accounts, covering WordPress, Joomla, Magento, and dozens of others, had its traffic intercepted for 33 hours. Softaculous has an enormous footprint. It is the mechanism through which millions of websites running on shared hosting keep their applications updated and installed.

For 33 hours, traffic between Softaculous infrastructure and its users was redirected. Softaculous has advised customers to reset credentials and to audit their installations for malicious packages.

Thirty-three hours is a long time. That is not a brief window. That is a working day and a half of potential exposure across a widely-used hosting supply chain.

Who this affects: Any UK business running a website on shared hosting where Softaculous manages application installations. This is the majority of small business websites running WordPress or similar platforms through providers like cPanel-based hosts.

What to do:

  • Reset your hosting control panel credentials immediately.
  • Reset your database passwords.
  • Audit your installed plugins and themes for anything you did not install or that appeared recently without your knowledge.
  • Check your website files for injected code, your hosting provider may offer a malware scan tool.
  • If you run an e-commerce site, treat customer payment data as potentially at risk and review your obligations under UK GDPR.

The Wider Context Worth Noting

These three stories do not exist in isolation. The BGP hijack of Softaculous is a supply chain attack, the attacker did not compromise individual websites, they compromised the infrastructure those websites depend on. PaperCut exploitation follows the now-standard pattern of zero-day to patch to active exploitation in days. The Exchange situation is a reminder that patch management at scale is an organisational discipline problem, not a technical one.

Also worth flagging from this week’s broader threat intelligence: the Spring Ring vishing campaign documented by Palo Alto Unit 42 recorded over 150 employees across at least 10 companies being targeted through Microsoft Teams voice phishing between January and April 2026. Attackers impersonated IT help desk personnel and coerced victims into running remote monitoring tools. The Microsoft Teams vector is specifically relevant to UK SMBs because Teams adoption has been high since the pandemic and staff are conditioned to trust it as an internal communications channel. It is not an internal communications channel if the external access controls are not properly configured.

Separately, Microsoft’s own documentation of the TerminalFix campaign, a ClickFix variant using fake Cloudflare CAPTCHA pages to trick users into running malicious PowerShell, is a reminder that the initial access vector is increasingly the user, not the perimeter. Fake CAPTCHAs are now a standard delivery mechanism for multi-stage intrusions.


Summary: Three Actions for Today

  1. Exchange on-premises: Confirm CVE-2026-62911 patch status with your IT provider today, in writing.
  2. PaperCut: Confirm patch applied, confirm no signs of compromise in the window before patching.
  3. Shared hosting: Reset credentials, audit installed packages, check for injected code.

If your IT provider cannot give you a clear answer on any of these within a working day, that is a conversation about your service level agreement, not just about these specific vulnerabilities.


Before tomorrow’s briefing: if Threat Analysis is useful to you, follow the show wherever you listen, the next briefing will land automatically. And if someone in your network is running on-premises Exchange or a shared hosting site, pass this along. The people who most need the heads-up are often the last to see it.


Sources

SourceTitleURL
BleepingComputerNearly 22,000 Microsoft Exchange servers vulnerable to hijack attackshttps://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/
BleepingComputerRecently patched PaperCut zero-days used in data theft attackshttps://www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used-in-data-theft-attacks/
The Register33-hour BGP hijack of Softaculous traffic prompts security scramblehttps://www.theregister.com/security/2026/09/01/33-hour-bgp-hijack-of-softaculous-traffic-prompts-security-scramble/5293608
Palo Alto Unit 42An Inside Look at Voice Phishing Campaigns in Microsoft Teamshttps://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/
Microsoft Security BlogTerminalFix campaign deploys a reverse tunnel through multistage intrusionhttps://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/

Filed under

  • smb-security
  • uk-business
  • supply-chain-risk
  • vendor-risk
  • incident-response
  • remote-access
  • business-risk