Attackers chain unpatched AhsayCBS flaws to hijack backup servers and mine crypto

Huntress says two chained AhsayCBS bugs are being exploited for unauthenticated SYSTEM-level code execution, and the latest version 10.3.4 is still affected.

Attackers chain unpatched AhsayCBS flaws to hijack backup servers and mine crypto

At a glance

  • CVE-2026-105133 (authentication bypass) and CVE-2026-105134 (OS command injection, CVSS v4 9.3) are being chained in the wild.
  • Huntress says attacks began on October 7 and at least five organizations were targeted by October 8.
  • Attackers dropped JSP web shells and XMRig miners disguised as Microsoft Edge, in one case loading the vulnerable WinRing0x64.sys driver.
  • Huntress reports version 10.3.4 is also vulnerable; restricting access to the management interface is the main mitigation.

Attackers are chaining two vulnerabilities in AhsayCBS, a centralized cloud backup server and management console from Ahsay Systems that is widely used by managed service providers (MSPs) and system integrators, to gain unauthenticated remote code execution with SYSTEM privileges, SecurityWeek and The Hacker News reported on October 9, citing security firm Huntress. According to Huntress, even the latest release appears to be affected, effectively leaving exposed servers without a fix.

What happened

The flaws, tracked as CVE-2026-105133 and CVE-2026-105134, were published on October 4, when NIST warned that exploit code targeting them had been released, SecurityWeek reported. Huntress said it observed exploitation beginning on October 7 at 11:20 p.m. UTC, and that at least five organizations had been targeted as of October 8.

The NVD entries state the issues were fixed in version 10.3.4, but Huntress reported that 10.3.4 is also affected, according to both publications. SecurityWeek describes the bugs as unpatched, and Huntress advises restricting access "until a patch is available."

Technical details

According to The Hacker News, CVE-2026-105133 (CVSS v4 5.5) is an improper authentication issue in the checkSysPwd() function, while CVE-2026-105134 (CVSS v4 9.3) is an OS command injection flaw in the Replication Receiver component. SecurityWeek reported that an API in that component accepts a random token in place of valid credentials, and chaining the two bugs lets a remote attacker bypass authentication and run commands as SYSTEM.

In observed attacks, an intruder configured a malicious receiver and dropped a JSP web shell into the application directory served by CBS, then performed reconnaissance. The attackers deployed XMRig cryptocurrency miners named edge.exe to pose as Microsoft Edge and created a persistence service masquerading as Microsoft Edge Update that runs a modified copy of the NSSM utility. A PowerShell script named Taskgmr.ps1, which Huntress suspects was AI-assisted, pauses mining and kills Task Manager when it is left open. In at least one incident, certutil.exe was used to download the legitimate but vulnerable WinRing0x64.sys driver to the TEMP folder, likely to give the miner kernel-level access.

Who is affected

NIST says all AhsayCBS versions up to 10.3.2 are affected, while Huntress says 10.3.4 is vulnerable as well. Because the exploit targets the externally accessible web application, internet-facing management consoles are most at risk. Backup servers typically hold sensitive data and broad network access, so the current cryptomining activity could be followed by more damaging intrusions.

What to do

Huntress recommends restricting web access to the AhsayCBS management interface to trusted IP addresses only or placing it behind a VPN. Administrators should also hunt for signs of compromise, including unexpected JSP files in the CBS web directory, processes or services named after Microsoft Edge running from unusual paths, the Taskgmr.ps1 script and WinRing0x64.sys in temporary folders, and should watch Ahsay Systems' channels for a confirmed fix.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.