CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

AhsayCBS, Replication Receiver /rps/api/json/UpdateReceivers.do unauthenticated code execution as SYSTEM (VulDB CVSS 4.0 10.0), exploited from 2026-10-07; 10.3.4 also affected per Huntress

cve · CVE-2026-105134 single-source

Coverage
1
first 2026-10-10 → last 2026-10-10
Latest activity
2026-10-10
Huntress: AhsayCBS flaws are exploited for SYSTEM-level code execution, and 10.3.4 is also affected
Peak priority
notable
1 notable
Targets
technology
sectors: technology
Sources cited
4
4 hosts

Action items (2)

Do-now tasks recorded on the entries about CVE-2026-105134, newest first. Check the date before acting on an older one.

  • Find every AhsayCBS server your organisation or your managed-service suppliers run and put its management web interface behind a VPN or an allowlist of trusted addresses now: Huntress found 10.3.4, which BleepingComputer calls the latest version, also affected, so upgrading is not a mitigation until Ahsay names a fixed release.
    2026-10-10CVE-2026-105133 +1
  • On any AhsayCBS server that was internet-reachable since 2026-10-04, check for the artifacts Huntress describes (children of the service downloading into Temp folders, new .jsp files in the application directory, a service that mimics the Edge updater) and re-image a host with a confirmed compromise from a trusted backup, as Huntress advises.
    2026-10-10CVE-2026-105133 +1

Defender insights

What each entry about CVE-2026-105134 tells a defender to do, newest first.

2026-10-10NOTABLEexploitedHuntress: AhsayCBS flaws are exploited for SYSTEM-level code execution, and 10.3.4 is also affected

Exposure · triage · detection

Story timeline

  1. 2026-10-10CVE-2026-105133 / CVE-2026-105134, AhsayCBS backup management console: an unauthenticated authentication-bypass and code-execution chain exploited since 7 October to drop webshells and a cryptominer, with 10.3.4 also affected and no fixed release named
    trending-vulnerabilitiesHuntress: AhsayCBS flaws are exploited for SYSTEM-level code execution, and 10.3.4 is also affected
ATT&CK techniques (16 across 9 tactics)

16 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Resource DevelopmentStage Capabilities: Upload Malware
  • Initial AccessExploit Public-Facing Application
  • ExecutionCommand and Scripting Interpreter: PowerShell · Command and Scripting Interpreter: Windows Command Shell · System Services: Service Execution
  • PersistenceServer Software Component: Web Shell · Create or Modify System Process: Windows Service
  • Privilege EscalationCreate or Modify System Process: Windows Service
  • StealthMasquerading: Masquerade Task or Service · Masquerading: Match Legitimate Resource Name or Location · Hide Artifacts
  • DiscoveryProcess Discovery · System Time Discovery
  • Command and ControlApplication Layer Protocol: Web Protocols · Ingress Tool Transfer · Non-Standard Port
  • ImpactResource Hijacking: Compute Hijacking

Resource Development TA0042

T1608.001Stage Capabilities: Upload Malware×1

Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include payloads, droppers, post-compromise tools, backdoors, and a variety of other malicious content. Adversaries may upload malware to support their operations, such as making a payload available to a victim network to enable Ingress Tool Transfer by placing it on an Internet accessible web server.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

Execution TA0002

T1059.001Command and Scripting Interpreter: PowerShell×1

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

T1059.003Command and Scripting Interpreter: Windows Command Shell×1

Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

T1569.002System Services: Service Execution×1

Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>services.exe</code>) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as <code>sc.exe</code> and Net.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

Persistence TA0003

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

Privilege Escalation TA0004

T1543.003Create or Modify System Process: Windows Service×1

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

Stealth TA0005

T1036.004Masquerading: Masquerade Task or Service×1

Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description. Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

T1036.005Masquerading: Match Legitimate Resource Name or Location×1

Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

T1564Hide Artifacts×1

Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

Discovery TA0007

T1057Process Discovery×1

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

T1124System Time Discovery×1

An adversary may gather the system time and/or time zone settings from a local or remote system. The system time is set and stored by services, such as the Windows Time Service on Windows or <code>systemsetup</code> on macOS. These time settings may also be synchronized between systems and services in an enterprise network, typically accomplished with a network time server within a domain.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

T1571Non-Standard Port×1

Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443. Adversaries may make changes to the standard port used by a protocol to bypass filtering or muddle analysis/parsing of network data.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

Impact TA0040

T1496.001Resource Hijacking: Compute Hijacking×1

Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

Evidence: 2026-10-10/ahsaycbs-cve-2026-105133-105134-exploited-webshells-xmrig · ATT&CK page ↗

Entries about AhsayCBS, Replication Receiver /rps/api/json/UpdateReceivers.do unauthenticated code execution as SYSTEM (VulDB CVSS 4.0 10.0), exploited from 2026-10-07; 10.3.4 also affected per Huntress (1)

2026-10-10 · view entry permalink →

NOTABLECVE-2026-105133 +1exploitedNATOB2

CVE-2026-105133 / CVE-2026-105134, AhsayCBS backup management console: an unauthenticated authentication-bypass and code-execution chain exploited since 7 October to drop webshells and a cryptominer, with 10.3.4 also affected and no fixed release named

Huntress reports that from 2026-10-07 23:20 UTC attackers exploited two flaws in AhsayCBS, the management console of Ahsay's backup software that managed service providers and system integrators mainly use, to gain unauthenticated remote code execution and deploy webshells on exposed servers (Huntress, 2026-10-08). CVE-2026-105133, an improper-authentication flaw in the checkSysPwd function of the API, is used first to bypass authentication; CVE-2026-105134, in the /rps/api/json/UpdateReceivers.do endpoint of the Replication Receiver component, then gives code execution as NT AUTHORITY\SYSTEM, after which the attacker configured a malicious receiver and dropped a JSP webshell into the directory the application serves (Huntress, 2026-10-08). BleepingComputer reports that the activity targeted at least five organizations on 7 October and that CVE-2026-105133 has a public exploit (BleepingComputer, 2026-10-09).

Follow-on activity, per Huntress: commands spawned by the AhsayCBS service process fetch payloads over HTTP from cloud object storage into a Temp folder with curl and certutil; an XMRig Monero miner renamed to look like a Microsoft Edge binary runs as SYSTEM through a service that mimics the Edge updater and a renamed copy of the NSSM service manager, and reaches its mining pool on a non-standard port; and a PowerShell script that Huntress assesses as AI-assisted checks whether Task Manager is running, uses the host's local time to decide when to close it, and stops the miner while it is open (Huntress, 2026-10-08). The patch position is contested: public records listed AhsayCBS up to 10.3.2 as affected (SecurityWeek, 2026-10-09), while Huntress's update of 2026-10-08 says 10.3.4 is also affected, that it has told Ahsay, and that owners should restrict the management interface until a patch is available (Huntress, 2026-10-08), and BleepingComputer calls 10.3.4 the latest version (BleepingComputer, 2026-10-09); Ahsay's release notes for 10.3.4 list no security fix (Ahsay, 2026-08-05).

Triage: AhsayCBS legitimately spawns its own startup and maintenance commands, so a child process alone is weak; the discriminators Huntress gives are a child of the service that downloads files into a Temp folder, and an Edge-named binary run as SYSTEM from a Temp folder under a service that mimics the Edge updater (Huntress, 2026-10-08).

Starting 2026-10-07 23:20:15 UTC, Huntress observed threat actors exploiting the vulnerabilities to gain unauthenticated remote code execution and deploy webshells on exposed systems.

After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities.

Until a patch is available, we recommend restricting access to the management interface and investigating for signs of compromise.

Huntress 2026-10-08

The malicious activity was observed on October 7, and targeted at least five organizations.

BleepingComputer 2026-10-09
vulnerability10 Oct 03:51Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • ahsay.com1 (25%)
  • bleepingcomputer.com1 (25%)
  • huntress.com1 (25%)
  • securityweek.com1 (25%)