Breaking
Cyber CrimeConfirmed

Unpatched AhsayCBS Bugs Exploited as Zero-Days

Attackers are chaining two unpatched AhsayCBS vulnerabilities to gain remote code execution and deploy webshells, with at least five organizations targeted.

··3 hours ago·3 min read
a close up of a computer in a dark room
Photo by Tyler on Unsplash

Two unpatched vulnerabilities in AhsayCBS are being exploited in the wild, providing attackers with remote code execution. The flaws remain without a fix, and the latest version of the software is affected.

The AhsayCBS management console is widely used by managed service providers and system integrators for backup policy, storage, and user management. The active exploitation of these flaws puts those environments at risk.

Two bugs, one goal

Tracked as CVE-2026-105133 and CVE-2026-105134, the vulnerabilities allow attackers to manipulate arguments in certain functions of the tool to bypass authentication and inject OS commands. They were disclosed on October 4, when NIST warned that exploit code targeting them had been released, and that all AhsayCBS versions up to 10.3.2 were affected.

On Thursday, Huntress warned that attackers have exploited the two flaws in the wild and that the latest AhsayCBS version, 10.3.4, is also affected.

According to Huntress, threat actors are chaining the two bugs to access vulnerable systems and execute arbitrary code on them. As of October 8, at least five organizations had been targeted.

Authentication bypass, then execution

CVE-2026-105134 can be exploited for unauthenticated RCE with System privileges through an API of the Replication Receiver component, Huntress warns.

“The API contains an authentication bypass that could allow for a random token to substitute valid credentials. After exploitation, a threat actor configured a malicious receiver and dropped a Java Server Page (JSP) webshell into the application directory served by the CBS application,” Huntress explains.

— Huntress, cybersecurity firm

Once inside, the attackers conducted reconnaissance and deployed XMRig cryptominers disguised as Microsoft Edge. They also planted an AI-assisted PowerShell script to monitor Task Manager and terminate it if it remains open for too long.

Persistence and kernel abuse

To maintain a foothold, the attackers created a Windows service masquerading as Microsoft Edge Update. This service executes a modified copy of the legitimate NSSM utility renamed msedge.exe with System privileges.

“NSSM can support other programs to ensure they stay running and restart after a crash or reboot, and threat actors in this incident likely used it to maintain persistence for edge.exe, while disguising the service-related binary as a legitimate-looking file,” Huntress notes.

— Huntress, cybersecurity firm

In one attack, the hackers deployed WinRing0x64.sys, a legitimate but vulnerable kernel driver that enabled the cryptocurrency miner to operate with kernel-level access.

No patch, so restrict

Until a patch is available, organizations should restrict access to the management interface and investigate for signs of compromise. Huntress offers specific guidance on hardening the attack surface.

“Organizations should restrict AhsayCBS management interface web access, as the exploit targets the externally accessible web app service on the host. Access should be limited to trusted IP addresses only or require VPN,” Huntress recommends.

— Huntress, cybersecurity firm

What defenders can do now

The absence of a vendor patch makes mitigation urgent. Huntress recommends limiting management interface exposure to trusted IPs or requiring VPN access. Monitoring for webshells, unusual service creation, and cryptomining activity is also critical.

The attackers’ use of a renamed NSSM binary and a legitimate kernel driver highlights the need to watch for living-off-the-land techniques. Detecting the JSP webshell and the XMRig miner disguised as Edge could help identify compromised systems.

Key figures from the incident

  • Two unpatched vulnerabilities: CVE-2026-105133 and CVE-2026-105134.
  • Disclosed on October 4 by NIST.
  • All AhsayCBS versions up to 10.3.2 affected; version 10.3.4 also affected.
  • At least five organizations targeted as of October 8.
  • Exploitation leads to unauthenticated RCE with System privileges.

Why it matters

For MSPs and organizations running AhsayCBS, the window to act is now. With no patch available, restricting management interface access and hunting for the described indicators is the only defense. The chaining of an authentication bypass with command injection, followed by webshell deployment and cryptomining, shows how quickly an exposed backup console can become a foothold for broader compromise. Ignoring these warnings could leave critical backup infrastructure open to persistent attackers.

#ahsaycbs#vulnerability#remote code execution#webshell#cryptomining

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories