AhsayCBS, Replication Receiver /rps/api/json/UpdateReceivers.do unauthenticated code execution as SYSTEM (VulDB CVSS 4.0 10.0), exploited from 2026-10-07; 10.3.4 also affected per Huntress
cve · CVE-2026-105134 single-source
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-105134, newest first. Check the date before acting on an older one.
- Find every AhsayCBS server your organisation or your managed-service suppliers run and put its management web interface behind a VPN or an allowlist of trusted addresses now: Huntress found 10.3.4, which BleepingComputer calls the latest version, also affected, so upgrading is not a mitigation until Ahsay names a fixed release.2026-10-10CVE-2026-105133 +1
- On any AhsayCBS server that was internet-reachable since 2026-10-04, check for the artifacts Huntress describes (children of the service downloading into Temp folders, new .jsp files in the application directory, a service that mimics the Edge updater) and re-image a host with a confirmed compromise from a trusted backup, as Huntress advises.2026-10-10CVE-2026-105133 +1
Defender insights
What each entry about CVE-2026-105134 tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (16 across 9 tactics)
16 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Resource DevelopmentStage Capabilities: Upload Malware
- Initial AccessExploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: Windows Command Shell · System Services: Service Execution
- PersistenceServer Software Component: Web Shell · Create or Modify System Process: Windows Service
- Privilege EscalationCreate or Modify System Process: Windows Service
- StealthMasquerading: Masquerade Task or Service · Masquerading: Match Legitimate Resource Name or Location · Hide Artifacts
- DiscoveryProcess Discovery · System Time Discovery
- Command and ControlApplication Layer Protocol: Web Protocols · Ingress Tool Transfer · Non-Standard Port
- ImpactResource Hijacking: Compute Hijacking
Resource Development TA0042
T1608.001Stage Capabilities: Upload Malware×1
Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, and a variety of other malicious content. Adversaries may upload malware to support their operations, such as making a payload available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web server.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
Execution TA0002
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
T1059.003Command and Scripting Interpreter: Windows Command Shell×1
Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
T1569.002System Services: Service Execution×1
Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>services.exe</code>) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as <code>sc.exe</code> and Net.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
Privilege Escalation TA0004
T1543.003Create or Modify System Process: Windows Service×1
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
Stealth TA0005
T1036.004Masquerading: Masquerade Task or Service×1
Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description. Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
T1564Hide Artifacts×1
Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
Discovery TA0007
T1057Process Discovery×1
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
T1124System Time Discovery×1
An adversary may gather the system time and/or time zone settings from a local or remote system. The system time is set and stored by services, such as the Windows Time Service on Windows or <code>systemsetup</code> on macOS. These time settings may also be synchronized between systems and services in an enterprise network, typically accomplished with a network time server within a domain.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
Command and Control TA0011
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
T1571Non-Standard Port×1
Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
Impact TA0040
T1496.001Resource Hijacking: Compute Hijacking×1
Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗
Entries about AhsayCBS, Replication Receiver /rps/api/json/UpdateReceivers.do unauthenticated code execution as SYSTEM (VulDB CVSS 4.0 10.0), exploited from 2026-10-07; 10.3.4 also affected per Huntress (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Ahsay AhsayCBS×1
- AhsayCBS, improper authentication in the API checkSysPwd function, chained with CVE-2026-105134 for unauthenticated code execution; exploited from 2026-10-07 (Huntress)×1
Where this entity is cited
Source distribution
- ahsay.com1 (25%)
- bleepingcomputer.com1 (25%)
- huntress.com1 (25%)
- securityweek.com1 (25%)
External references
All cited sources (4)
- huntress.comprimaryHuntresshttps://www.huntress.com/blog/ahsaycbs-flaws-exploit
- ahsay.comAhsay (AhsayCBS 10.3.4 release notes)https://www.ahsay.com/en/support/help-centre/release-notes/cbs/v10.3.4
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/
- securityweek.comSecurityWeekhttps://www.securityweek.com/unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild/