Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Unpatched AhsayCBS vulnerabilities CVE-2026-105133 and CVE-2026-105134 are being exploited in the wild.
Summary
Attackers are actively exploiting two unpatched vulnerabilities, CVE-2026-105133 and CVE-2026-105134, in the AhsayCBS backup solution to achieve remote code execution. These flaws allow for authentication bypass and OS command injection, enabling threat actors to deploy webshells, cryptominers (XMRig), and achieve persistence using disguised Windows services. Huntress warns that all versions up to 10.3.2, and even 10.3.4, are affected, recommending access restrictions until a patch is available.
Full text
Hackers have been exploiting two unpatched vulnerabilities in the AhsayCBS backup solution for remote code execution (RCE), cybersecurity firm Huntress warns. A centralized cloud backup server management console developed by Ahsay Systems, AhsayCBS provides backup policy, storage, and user management and is popular among MSPs and system integrators. Tracked as CVE-2026-105133 and CVE-2026-105134, the exploited security defects allow attackers to manipulate arguments in certain functions of the tool to bypass authentication and inject OS commands. They were disclosed on October 4, when NIST warned that exploit code targeting them had been released, and that all AhsayCBS versions up to 10.3.2 were affected. On Thursday, Huntress warned that attackers have exploited the two flaws in the wild and that the latest AhsayCBS version, 10.3.4, is also affected. “Until a patch is available, we recommend restricting access to the management interface and investigating for signs of compromise,” Huntress says.Advertisement. Scroll to continue reading. According to Huntress, threat actors are chaining the two bugs to access vulnerable systems and execute arbitrary code on them. As of October 8, at least five organizations had been targeted. “Huntress observed threat actors exploiting the vulnerabilities to gain unauthenticated remote code execution and deploy webshells on exposed systems,” the cybersecurity firm notes. It also warns that CVE-2026-105134 can be exploited for unauthenticated RCE with System privileges through an API of the Replication Receiver component. “The API contains an authentication bypass that could allow for a random token to substitute valid credentials. After exploitation, a threat actor configured a malicious receiver and dropped a Java Server Page (JSP) webshell into the application directory served by the CBS application,” Huntress explains. After gaining initial access, the attackers conducted reconnaissance and deployed XMRig cryptominers disguised as Microsoft Edge. They also planted an AI-assisted PowerShell script to monitor Task Manager and terminate it if it remains open for too long. They also achieved persistence by creating a Windows service masquerading as Microsoft Edge Update to execute a modified copy of the legitimate NSSM utility named msedge.exe with System privileges. “NSSM can support other programs to ensure they stay running and restart after a crash or reboot, and threat actors in this incident likely used it to maintain persistence for edge.exe, while disguising the service-related binary as a legitimate-looking file,” Huntress notes. In one attack, the hackers deployed WinRing0x64.sys, a legitimate but vulnerable kernel driver that enabled the cryptocurrency miner to operate with kernel-level access. “Organizations should restrict AhsayCBS management interface web access, as the exploit targets the externally accessible web app service on the host. Access should be limited to trusted IP addresses only or require VPN,” Huntress recommends. Related: Citrix Urges Immediate Patching of Critical NetScaler Vulnerability Related: Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own Related: Cisco Patches a Dozen Critical Vulnerabilities Related: Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire SonicWall and Splunk Patch Critical VulnerabilitiesRein Security Raises $25 Million to Guard AI Agents at RuntimeFake Decryption Tools Masked $11M Markup in Ransomware Recovery SchemeFortiBleed Attackers Locking Victims Out of Fortinet DevicesQilin Ransomware Suspect Arrested in Japan, Extradited to GermanyChrome 155 Update Patches 247 VulnerabilitiesASOS Confirms Cyberattack, Data BreachAndroid’s October 2026 Updates Patch 25 Vulnerabilities Latest News Pre-Baked Firmware Malware Hits Budget Android Devices in 150+ CountriesUS Disrupts Chinese State-Sponsored Hacking ToolsAnthropic Fast-Tracks AI Bug Reports to OSS Maintainers, Taps 11 Firms for OT SecurityCitrix Urges Immediate Patching of Critical NetScaler VulnerabilityGoogle Pixel 10 Exploits Earned Hackers $560,000 at Pwn2OwnFormula Predicts When AI Chatbots Are at Risk of Turning BadCisco Patches a Dozen Critical VulnerabilitiesSecurity Awareness Training Isn’t Dead, but It Needs a Rethink Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveRapid7 has named Rik Ferguson as VP of Security Intelligence.Cytactic has appointed Tim Brown as CSO.Scott Simkin has joined Vega as CMO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- cve — CVE-2026-105133
- cve — CVE-2026-105134
- malware — XMRig
- malware — webshell