Back to Feed
MalwareOct 9, 2026

Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

Unpatched AhsayCBS flaws exploited for webshells and crypto mining.

Summary

Threat actors are actively exploiting two unpatched vulnerabilities in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. The vulnerabilities, CVE-2026-105133 and CVE-2026-105134, are chained to bypass authentication and execute commands, leading to the installation of XMRig miners and potentially backdoors. Huntress MDR has identified indicators of compromise and recommends restricting access to the management interface.

Full text

Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto By Bill Toulas October 9, 2026 01:17 PM 0 Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. AhsayCBS is typically used by managed service providers (MSPs) and system integrators. The malicious activity was observed on October 7, and targeted at least five organizations. The two security issues exploited in attacks are tracked as CVE-2026-105133, an authentication bypass vulnerability that has a public exploit, and CVE-2026-105134, which can be leveraged for OS command injection. Both vulnerabilities are reported as fixed in AhsayCBS 10.3.2, but researchers at managed detection and response company (MDR) Huntress found that they also affect Ahsay 10.3.4, currently the latest version. "After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities," Huntress says in an update today. In the observed attacks, the threat actor chained the two vulnerabilities, CVE-2026-105133 first to bypass authentication and then CVE-2026-105134 for code execution. After gaining access, Huntress observed the attacker perform reconnaissance, deploy Java Server Page (JSP) webshells, and download the XMRig miner disguised as edge.exe. The miner persists on the host via a service named ‘MicrosoftEdgeUpdateSvc,’ which runs msedge.exe, identified by Huntress as a modified copy of the legitimate Non-Sucking Service Manager (NSSM) utility. A PowerShell file (Taskgmr.ps1) that Huntress believes to be an AI-assisted script conceals mining activity by stopping the service when Task Manager opens and restarting it when Task Manager closes. The script also terminates Task Manager at 6 p.m. local time or if it remains open for more than an hour overnight. In one case, the attacker also deployed the vulnerable WinRing0x64.sys driver, likely in an attempt to unlock more hardware resources for the miner. BleepingComputer has contacted AhsayCBS to ask about its plans to fix the two flaws, but we have not heard back as of publication. Until a patch is available, Huntress recommends that system administrators restrict access to the AhsayCBS management interface to trusted IP addresses only, and investigate signs of compromise. If a compromise is confirmed, administrators should perform a full restore of the host from a safe backup, because the attacker may have installed additional backdoors for prolonged persistence. Huntress has also provided indicators of compromise (IoCs) for this activity, along with four Sigma rules to help defenders detect it. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Hackers exploit macOS Screen Sharing flaw to deploy Monero minerCheck Point warns of hackers exploiting Security Gateway VPN RCE flawHackers start exploiting critical WordPress flaw for code executionF5 patches BIG-IP APM zero-day flaw exploited in RCE attacksAcronis warns of actively exploited flaw in its cPanel backup plugin

Indicators of Compromise

  • cve — CVE-2026-105133
  • cve — CVE-2026-105134
  • malware — XMRig
  • malware — JSP webshells
  • malware — edge.exe
  • malware — MicrosoftEdgeUpdateSvc
  • malware — Taskgmr.ps1
  • malware — WinRing0x64.sys

Entities

AhsayCBS (product)XMRig (product)JSP webshells (technology)NSSM (technology)Huntress (vendor)