Back to advisories

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service persistence. Any organization running affected versions is at immediate risk of full system compromise.

CRITICALAdvisoryOct 10, 2026
Action required
Immediately restrict network access to AhsayCBS instances to trusted IPs only. Hunt for XMRig processes, suspicious webshells in web directories, and disguised Windows services on all systems running AhsayCBS 10.3.4 and earlier. Escalate any findings to incident response.
Affected products
AhsayCBSAhsay SystemsXMRigNSSMWinRing0x64.sys