Home / Blog / Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Tech News

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Two unpatched AhsayCBS flaws are being chained in live attacks to deliver cryptominers and webshells, with version 10.3.4 still exposed and no fix available.

By Dillip Chowdary • Oct 10, 2026 • Source: SecurityWeek

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Huntress warned on October 9, 2026, that attackers have been actively exploiting two unpatched vulnerabilities in AhsayCBS, a centralized cloud backup server management console from Ahsay Systems, to achieve remote code execution on exposed systems. According to SecurityWeek's report, the vulnerabilities are being chained together in real-world attacks, and even the latest available version of the software, 10.3.4, remains vulnerable with no patch currently available.

This article covers the technical mechanics of the two flaws, how attackers have weaponized them to deploy cryptominers and webshells, which organizations face the highest exposure, and what defenders can do right now. It is aimed at IT administrators, managed service providers, and security teams who rely on or support AhsayCBS deployments.

Unpatched AhsayCBS Vulnerabilities Exploited: what actually changed

NIST disclosed CVE-2026-105133 and CVE-2026-105134 on October 4, 2026, noting at the time that exploit code had already been published and that all AhsayCBS versions up to 10.3.2 were affected. That initial advisory prompted urgent attention, but the situation deteriorated quickly. On October 9, Huntress confirmed that threat actors had moved from proof-of-concept exploitation to active campaigns in the wild, and critically, that version 10.3.4 — the newest release — provides no protection against either flaw.

The shift from disclosed-but-patching to actively-exploited-with-no-fix-available is a meaningful escalation. Organizations that assumed upgrading to 10.3.4 was sufficient mitigation are now exposed. Huntress's recommendation is direct: restrict access to the AhsayCBS management interface immediately and investigate any previously exposed systems for indicators of compromise. No patch timeline was provided by Ahsay Systems as of the Huntress disclosure.

Unpatched AhsayCBS Vulnerabilities Exploited: how it works

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Illustration · Pexels

The two CVEs work together as a chain. CVE-2026-105133 allows attackers to manipulate arguments in certain functions of AhsayCBS to bypass authentication. CVE-2026-105134 goes further: it targets the API of the Replication Receiver component and can be exploited for unauthenticated remote code execution with System privileges. The API contains an authentication bypass that allows a random token to substitute for valid credentials, effectively removing the authentication layer entirely.

Once inside, Huntress observed attackers configuring a malicious receiver and dropping a Java Server Page webshell into the application directory served by the CBS application. That webshell provides persistent, interactive access to the compromised host without requiring re-exploitation. From that foothold, attackers then conducted reconnaissance and staged their secondary payloads, all operating under System-level privileges granted by CVE-2026-105134.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

Unpatched AhsayCBS Vulnerabilities Exploited: why it matters now

As of October 8, at least five organizations had been targeted in confirmed incidents. The payload mix observed by Huntress illustrates how thoroughly attackers had mapped out their post-exploitation plan. They deployed XMRig cryptominers disguised as Microsoft Edge, then went a step further by planting an AI-assisted PowerShell script to monitor Task Manager and terminate that process if it remained open too long — a direct attempt to prevent defenders from spotting the miner in real time.

Persistence was established by creating a Windows service that masqueraded as Microsoft Edge Update, which executed a modified copy of the legitimate NSSM utility renamed as msedge.exe with System privileges. NSSM is designed to keep programs running through crashes and reboots, meaning the attacker's tooling survived system restarts. In one attack, the hackers also deployed WinRing0x64.sys, a legitimate but vulnerable kernel driver, giving the cryptominer kernel-level access to the host. The combination of disguised process names, kernel access, and Task Manager monitoring reflects a sophisticated and deliberate operational security posture.

Unpatched AhsayCBS Vulnerabilities Exploited: who is affected

AhsayCBS is marketed specifically to managed service providers and system integrators as a centralized platform for managing backup policies, storage, and users across client environments. This customer profile is significant: a compromised AhsayCBS instance does not just expose the MSP's own infrastructure — it may provide a vantage point into multiple downstream client environments that the backup system touches. Any organization running any version of AhsayCBS up to and including 10.3.4 should treat itself as vulnerable until Ahsay Systems releases a patch.

Huntress specifically flagged that the exploit targets the externally accessible web application service on the host, meaning any AhsayCBS management interface reachable from the public internet is in scope for these attacks. Organizations that have placed the management console on a public IP, even with standard authentication in place, are directly exposed because CVE-2026-105134 bypasses that authentication entirely.

Unpatched AhsayCBS Vulnerabilities Exploited: what to watch

Huntress advises restricting AhsayCBS management interface web access to trusted IP addresses only, or routing access through a VPN, as the primary defensive action while no patch exists. Organizations should also audit any system that has had the management interface exposed and look for the specific indicators documented by Huntress: JSP webshells in the CBS application directory, processes or services using the name msedge.exe, presence of WinRing0x64.sys, XMRig miner activity, and PowerShell scripts configured to monitor Task Manager.

The absence of a patch from Ahsay Systems is the critical open variable. Huntress has not provided a vendor-confirmed remediation timeline, and there is no CVE status indicating a fix is imminent. Security teams should monitor Ahsay Systems' advisories directly and treat any Ahsay Systems patch release as a high-priority emergency deployment. Until then, network-level access controls remain the only effective mitigation.

Developer Action Items

  • ☐ Inventory whether Unpatched AhsayCBS Vulnerabilities Exploited runs in prod, CI, staging, or on laptops before you debate severity.
  • ☐ Pull the vendor advisory for CVE-2026-105133, CVE-2026-105134 and patch from that page — not from a social recap.
  • ☐ If you cannot patch today, isolate the service, rotate tokens that sat on the affected surface, and raise the logging floor.
  • ☐ Record the decision and residual risk so the next on-call does not re-litigate whether you are exposed.

Unpatched AhsayCBS Vulnerabilities Exploited FAQ

What are CVE-2026-105133 and CVE-2026-105134?

They are two security flaws in AhsayCBS that allow attackers to bypass authentication and inject OS commands, enabling unauthenticated remote code execution. CVE-2026-105134 specifically exploits the Replication Receiver API with System-level privileges.

Which versions of AhsayCBS are vulnerable?

All versions up to 10.3.2 were confirmed vulnerable at initial disclosure on October 4, 2026. Huntress subsequently confirmed that version 10.3.4, the latest available release, is also affected and unpatched.

Is there a patch available for these AhsayCBS vulnerabilities?

No patch was available as of the Huntress disclosure on October 9, 2026. The recommendation is to restrict access to the management interface to trusted IP addresses or require VPN access until a fix is released.

What did attackers do after exploiting AhsayCBS?

Attackers dropped JSP webshells, deployed XMRig cryptominers disguised as Microsoft Edge, used NSSM renamed as msedge.exe to maintain persistence, and in one case installed the WinRing0x64.sys kernel driver to give the miner kernel-level access.

Who is most at risk from these AhsayCBS exploits?

Managed service providers and system integrators are the primary AhsayCBS customer base and face the highest risk, as a compromised backup server could expose multiple downstream client environments. At least five organizations had been targeted as of October 8, 2026.

Sources

Dillip Chowdary

Author

Dillip Chowdary

Writes Tech Bytes coverage of AI, engineering, and the tools that actually ship. Editor of Tech Pulse Daily.

Related on Tech Bytes

Advertisement

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →