[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild-mv266gbi":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":14,"action_required":20,"article_ids":21,"ioc_summary":23,"source_urls":24,"status":26,"expires_at":27,"created_at":28,"updated_at":29,"articles":30},"0ede17ca-4e13-462a-be57-79dc34935442","Unpatched AhsayCBS Vulnerabilities Exploited in the Wild","unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild-mv266gbi","Attackers are actively exploiting two unpatched remote code execution flaws in AhsayCBS backup software versions up to 10.3.4. CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection, leading to webshell deployment, cryptominer installation, and Windows service persistence. Any organization running affected versions is at immediate risk of full system compromise.","critical","advisory",[12,13],"CVE-2026-105133","CVE-2026-105134",[15,16,17,18,19],"AhsayCBS","Ahsay Systems","XMRig","NSSM","WinRing0x64.sys","Immediately restrict network access to AhsayCBS instances to trusted IPs only. Hunt for XMRig processes, suspicious webshells in web directories, and disguised Windows services on all systems running AhsayCBS 10.3.4 and earlier. Escalate any findings to incident response.",[22],"6ae1d8c0-d8a1-47a2-9c54-80a32c5043f4",null,[25],"https:\u002F\u002Fwww.securityweek.com\u002Funpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild\u002F","active","2026-10-12T09:06:10.662+00:00","2026-10-10T09:06:13.977309+00:00","2026-10-10T09:07:17.313776+00:00",[31],{"id":22,"title":6,"url":25}]