Short answer: Hackers are actively exploiting two unpatched vulnerabilities in AhsayCBS backup management software to break into servers without any login credentials, install web shells, and run cryptocurrency miners with full SYSTEM privileges. The flaws are tracked as CVE-2026-105133 and CVE-2026-105134, in-the-wild attacks began on October 7, 2026, and at least five organizations have been targeted so far. Most concerning: the latest version of the software, 10.3.4, is also vulnerable, so simply being up to date does not protect you.
Here is what happened, how the attack works, and what administrators should do right now.
What Is AhsayCBS, and Why Does This Matter?
AhsayCBS (Ahsay Cloud Backup Server) is a centralized management console for the Ahsay backup platform. It is popular with managed service providers (MSPs) and system integrators, who use it to create user accounts, manage backup policies, and control storage destinations across their clients.
That role is exactly what makes this attack so dangerous. A compromised backup server can expose stored credentials, service accounts, backup repositories, and the trusted connections that link one deployment to many customers. In a worst-case scenario, an attacker who controls the backup infrastructure can tamper with recovery itself — undermining the one system a business counts on when everything else goes wrong.
The Two Vulnerabilities: CVE-2026-105133 and CVE-2026-105134
The two flaws were published to the US National Vulnerability Database (NVD) on October 4, 2026. At the time, NIST also warned that exploit code targeting the flaws had been made available. Here is what each one does:
CVE-2026-105133: Improper Authentication
This is a flaw in the checkSysPwd function of the AhsayCBS API component. By manipulating the “random” argument passed to this function, an attacker can substitute an arbitrary token for valid credentials — effectively bypassing authentication entirely. CVE records rate it at CVSS 7.3, while Huntress assessed it as medium severity.
CVE-2026-105134: OS Command Injection
This is the more serious of the two, rated CVSS 9.3 to 10.0. It affects the Replication Receiver component at the /rps/api/json/UpdateReceivers.do API endpoint. The same kind of argument manipulation allows an unauthenticated attacker to inject operating system commands that execute in the context of NT AUTHORITY\SYSTEM — the highest privilege level on a Windows machine.
Originally, the vulnerabilities were reported as fixed in version 10.3.2. However, Huntress later confirmed that the latest release, version 10.3.4, is also affected — meaning there is currently no vendor patch that resolves the issue.
How the Attack Works
Huntress first observed exploitation attempts on October 7, 2026 at 23:20 UTC, just three days after the vulnerabilities were disclosed. The attack chain is straightforward:
- Bypass authentication using CVE-2026-105133, substituting a random token for real credentials.
- Inject OS commands through CVE-2026-105134 via the Replication Receiver API endpoint.
- Configure a malicious replication receiver and drop a Java Server Page (JSP) web shell into the application directory served by AhsayCBS.
- Execute commands as SYSTEM, giving the attacker complete control of the server.
Huntress first spotted the activity through suspicious command lines spawned by the cbssvcX64.exe service, which is AhsayCBS’s main background process.
What the Attackers Did After Getting In
In the observed intrusions, the attackers moved through reconnaissance, web shell deployment, and finally installed XMRig cryptocurrency miners disguised as legitimate Microsoft Edge processes. The tricks used to stay hidden were unusually thorough:
- Disguised miners: The XMRig Monero miner was renamed to
edge.exeandmsedge.exeto blend in with the real browser. - Fake persistence service: A service named “MicrosoftEdgeUpdateSvc” was created so the miner restarts automatically. Huntress identified it as a modified copy of the legitimate Non-Sucking Service Manager (NSSM) utility.
- Task Manager evasion: A PowerShell script (
Taskgmr.ps1), which Huntress believes was AI-assisted, stops the mining service whenever Task Manager is opened and restarts it when Task Manager closes. It also terminates Task Manager at 6 p.m. local time or if it stays open for more than an hour overnight. - Hardware-boosting driver: In one case, the attacker installed the vulnerable
WinRing0x64.syskernel driver to unlock more hardware resources for the miner.
So far, all observed attacks have focused on cryptomining. But with SYSTEM-level access, the same foothold could be used for credential theft, backup manipulation, or as a launch point into the networks of every client the MSP serves. Those risks are potential rather than observed, but they are the reason security researchers are treating this seriously.
What to Do If You Run AhsayCBS
Until Ahsay releases a patch, Huntress recommends the following:
- Restrict access to the management interface — limit it to trusted administrative networks, approved source addresses, or VPN connections. Do not leave it exposed to the internet.
- Inventory every deployment — check production, disaster recovery, test, and secondary installations. Do not assume that upgrading to 10.3.4 fixed anything.
- Hunt for compromise — look for unexpected JSP files, suspicious child processes spawned by
cbssvcX64.exe, unauthorized receiver configurations, unexpected PowerShell execution, and mining-related outbound connections. - Rebuild if compromised — a software update alone may not remove changes the attackers made. Rebuild compromised hosts from known-good media and redeploy the application.
Why This Fits a Bigger Pattern
This attack is part of a busy October for infrastructure-targeting campaigns. Just days earlier, the FBI seized hacking tools linked to China’s Flax Typhoon operation, and attackers compromised the Tensorlake npm package to steal developer credentials at scale. Earlier zero-day stories like the SonicWall SMA 1000 SSRF flaw and the KVM VM-escape zero-day show the same playbook: hit the management layer, get privileged access, then decide what to monetize.
The speed matters too. These flaws went from NVD disclosure on October 4 to active exploitation on October 7 — three days. Patch windows are no longer measured in weeks; for internet-facing infrastructure, they are measured in days.
Frequently Asked Questions
Is AhsayCBS 10.3.4 safe?
No. Huntress confirmed that version 10.3.4, the latest release at the time of reporting, is also affected by both vulnerabilities. Until Ahsay issues a fixed version, treat all installations as vulnerable and restrict network access to the management interface.
Do the attackers need a password to exploit this?
No. The attack chain requires only network access to a vulnerable AhsayCBS interface. CVE-2026-105133 bypasses authentication, and CVE-2026-105134 then provides SYSTEM-level command execution — no valid credentials or user interaction needed.
What are the attackers doing with the compromised servers?
So far, all observed intrusions have deployed XMRig Monero cryptocurrency miners, disguised as Microsoft Edge processes and protected by a fake update service. But SYSTEM-level access could enable credential theft, backup tampering, or further lateral movement into client networks.
How can I tell if my AhsayCBS server was compromised?
Look for unexpected JSP files in the application directory, suspicious child processes spawned by cbssvcX64.exe, unauthorized replication receiver configurations, PowerShell scripts like Taskgmr.ps1, a service named “MicrosoftEdgeUpdateSvc”, and unexplained outbound connections consistent with mining traffic.
What is the CVSS score of the AhsayCBS vulnerabilities?
CVE-2026-105133 (improper authentication) is rated CVSS 7.3, and CVE-2026-105134 (OS command injection in the Replication Receiver) is rated CVSS 9.3 to 10.0 — critical. Chained together, they give an unauthenticated attacker remote code execution as NT AUTHORITY\SYSTEM.
