Unpatched AhsayCBS Backup Flaws Actively Exploited for Remote Code Execution
Attackers are actively exploiting two unpatched vulnerabilities in AhsayCBS — an authentication bypass (CVE-2026-105133) and an OS command injection flaw (CVE-2026-105134) — to achieve full remote code execution without credentials. The combination of these flaws is particularly dangerous because it requires no authentication, lowering the barrier for widespread exploitation. Threat actors are leveraging access to deploy webshells, cryptominers, and persistent backdoors disguised as legitimate Windows services, compounding the damage beyond initial compromise. This incident highlights the critical risk of exposing unpatched backup infrastructure directly to the internet, as backup systems often hold privileged access to sensitive data and environments.
Tactical Insight
Immediate actions
- Restrict all network access to AhsayCBS management interfaces to trusted IP ranges or VPN only until an official patch is available.
- Audit existing AhsayCBS deployments for signs of compromise, including unexpected webshells, new Windows services, and XMRig processes.
- Isolate any confirmed or suspected compromised systems from the broader network immediately.
Long-term improvements
- Establish a formal vulnerability management program that prioritizes internet-facing and backup infrastructure for rapid patching.
- Maintain an up-to-date inventory of all software and appliances, including version tracking, to enable fast identification of affected systems during active exploits.
- Implement network segmentation to ensure backup management consoles are never directly reachable from the public internet.
Detection measures
- Deploy file integrity monitoring and endpoint detection on backup servers to alert on unexpected executable creation or service installation.
- Enable centralized logging of all authentication attempts and administrative actions on backup systems and forward to a SIEM for real-time alerting.
- Subscribe to threat intelligence feeds and vendor security advisories to receive early warning of newly disclosed vulnerabilities in critical infrastructure software.