- Threat actors began exploiting the two AhsayCBS vulnerabilities on Oct 7 to gain unauthenticated remote code execution and deploy webshells.
- AhsayCBS version 10.3.4 was also affected, Huntress said, and five organizations had been targeted or affected by Oct 8, The Hacker News said.
Threat actors exploited two AhsayCBS vulnerabilities beginning at 23:20:15 UTC on Oct 7, deploying webshells on exposed systems, Huntress said. The campaign used CVE-2026-105133 and CVE-2026-105134 to gain unauthenticated remote code execution.
Ahsay Systems describes AhsayCBS as a centralized cloud backup server management console used by managed service providers and system integrators. The two vulnerabilities were identified on Oct 4, Huntress said.
On this page
The attackers chained authentication bypass and remote code execution flaws
CVE-2026-105133 affects the checkSysPwd function and can cause improper authentication. CVE-2026-105134 affects the Replication Receiver component and can provide unauthenticated remote code execution as NT AUTHORITY/SYSTEM on the host.
Huntress said attackers first used CVE-2026-105133 to bypass authentication, then used CVE-2026-105134 to gain code execution. The Hacker News attributed CVSS v4 scores of 5.5 and 9.3 to the two flaws, respectively.
NIST warned on Oct 4 that exploit code had been released and that AhsayCBS versions through 10.3.2 were affected, according to SecurityWeek.
AhsayCBS intrusions added webshells, miners and persistence
Huntress saw attackers deploy .jsp webshells in the web application directory immediately after exploitation. It also found XMRig miners named edge.exe in Temp folders, followed by miner network connections on port 8029 to an XMR pool.
Huntress said companies should carry out a full host re-image from a trusted backup if indicators of compromise listed in its blog are uncovered.
What to do now
- Carry out a full host re-image from a trusted backup if any listed indicators of compromise have been uncovered.
FAQ
What happened to AhsayCBS?
Threat actors exploited CVE-2026-105133 and CVE-2026-105134 beginning on Oct 7 to gain unauthenticated remote code execution and deploy webshells, XMRig miners and persistence mechanisms.
Which AhsayCBS versions are affected?
NIST warned that versions through 10.3.2 were affected, and Huntress later determined that version 10.3.4 was also affected.
Were the AhsayCBS flaws exploited in the wild?
Yes. Huntress observed exploitation beginning at 23:20:15 UTC on Oct 7, and The Hacker News said five organizations had been targeted or affected by Oct 8.
What are CVE-2026-105133 and CVE-2026-105134?
CVE-2026-105133 is an improper-authentication flaw in the checkSysPwd function. CVE-2026-105134 affects the Replication Receiver component and can provide unauthenticated remote code execution as NT AUTHORITY/SYSTEM.
Sources
- Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer | Huntress, HuntressPrimary
- Unpatched AhsayCBS Vulnerabilities Exploited in the Wild, SecurityWeek
- Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge, The Hacker News
- Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto, BleepingComputer
How we checked this story
| Claim | Source | Status |
|---|---|---|
| AhsayCBS is a centralized cloud backup server management console developed by Ahsay Systems and used by managed service providers and system integrators. | Ahsay Systems, via SecurityWeek | Attributed |
| Huntress said two vulnerabilities in AhsayCBS were identified on October 4, 2026. | Huntress | Confirmed |
| CVE-2026-105133 affects AhsayCBS’s checkSysPwd function and can cause improper authentication. | Huntress | Confirmed |
| CVE-2026-105134 affects the Replication Receiver component and can provide unauthenticated remote code execution as NT AUTHORITY/SYSTEM. | Huntress | Confirmed |
| Huntress observed attackers chaining the two vulnerabilities, first bypassing authentication and then gaining code execution. | Huntress | Confirmed |
| The two flaws were disclosed on October 4, when NIST warned that exploit code had been released and AhsayCBS versions through 10.3.2 were affected. | NIST, via SecurityWeek | Attributed |
| The Hacker News said cVE-2026-105134 has a CVSS v4 score of 9.3. | The Hacker News | Attributed |
| Huntress observed exploitation beginning at 23:20:15 UTC on October 7, 2026. | Huntress | Confirmed |
| Huntress observed XMRig miners renamed edge.exe connecting to an XMR pool on port 8029. | Huntress | Confirmed |
| The script killed Task Manager at 18:00 or when it had remained open for more than one hour overnight. | Huntress | Confirmed |
| Huntress published four Sigma rules for detecting this campaign’s post-exploitation activity. | Huntress | Confirmed |
| BleepingComputer reported that the exploited AhsayCBS flaws were one critical-severity and one medium-severity vulnerability. | BleepingComputer | Attributed |
| huntress.com published its report on Oct 8, 2026. | huntress.com | Confirmed |
Could not verify
- Whether Ahsay has released a patch is not established.
- Whether all five affected organizations were compromised is not established.
- Whether the attackers were linked to a named group is not established.



