CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLECVE-2026-105133 +1exploitedNATOB2vulnerability

CVE-2026-105133 / CVE-2026-105134, AhsayCBS backup management console: an unauthenticated authentication-bypass and code-execution chain exploited since 7 October to drop webshells and a cryptominer, with 10.3.4 also affected and no fixed release named

Huntress: AhsayCBS flaws are exploited for SYSTEM-level code execution, and 10.3.4 is also affected

Defender actions

  • Find every AhsayCBS server your organisation or your managed-service suppliers run and put its management web interface behind a VPN or an allowlist of trusted addresses now: Huntress found 10.3.4, which BleepingComputer calls the latest version, also affected, so upgrading is not a mitigation until Ahsay names a fixed release.
  • On any AhsayCBS server that was internet-reachable since 2026-10-04, check for the artifacts Huntress describes (children of the service downloading into Temp folders, new .jsp files in the application directory, a service that mimics the Edge updater) and re-image a host with a confirmed compromise from a trusted backup, as Huntress advises.

Analysis

Huntress reports that from 2026-10-07 23:20 UTC attackers exploited two flaws in AhsayCBS, the management console of Ahsay's backup software that managed service providers and system integrators mainly use, to gain unauthenticated remote code execution and deploy webshells on exposed servers (Huntress, 2026-10-08). CVE-2026-105133, an improper-authentication flaw in the checkSysPwd function of the API, is used first to bypass authentication; CVE-2026-105134, in the /rps/api/json/UpdateReceivers.do endpoint of the Replication Receiver component, then gives code execution as NT AUTHORITY\SYSTEM, after which the attacker configured a malicious receiver and dropped a JSP webshell into the directory the application serves (Huntress, 2026-10-08). BleepingComputer reports that the activity targeted at least five organizations on 7 October and that CVE-2026-105133 has a public exploit (BleepingComputer, 2026-10-09).

Follow-on activity, per Huntress: commands spawned by the AhsayCBS service process fetch payloads over HTTP from cloud object storage into a Temp folder with curl and certutil; an XMRig Monero miner renamed to look like a Microsoft Edge binary runs as SYSTEM through a service that mimics the Edge updater and a renamed copy of the NSSM service manager, and reaches its mining pool on a non-standard port; and a PowerShell script that Huntress assesses as AI-assisted checks whether Task Manager is running, uses the host's local time to decide when to close it, and stops the miner while it is open (Huntress, 2026-10-08). The patch position is contested: public records listed AhsayCBS up to 10.3.2 as affected (SecurityWeek, 2026-10-09), while Huntress's update of 2026-10-08 says 10.3.4 is also affected, that it has told Ahsay, and that owners should restrict the management interface until a patch is available (Huntress, 2026-10-08), and BleepingComputer calls 10.3.4 the latest version (BleepingComputer, 2026-10-09); Ahsay's release notes for 10.3.4 list no security fix (Ahsay, 2026-08-05).

Triage: AhsayCBS legitimately spawns its own startup and maintenance commands, so a child process alone is weak; the discriminators Huntress gives are a child of the service that downloads files into a Temp folder, and an Edge-named binary run as SYSTEM from a Temp folder under a service that mimics the Edge updater (Huntress, 2026-10-08).

Cited evidence

Starting 2026-10-07 23:20:15 UTC, Huntress observed threat actors exploiting the vulnerabilities to gain unauthenticated remote code execution and deploy webshells on exposed systems.

After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities.

Until a patch is available, we recommend restricting access to the management interface and investigating for signs of compromise.

Huntress 2026-10-08

The malicious activity was observed on October 7, and targeted at least five organizations.

BleepingComputer 2026-10-09

Sources4

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.