---
schema: 1
kind: vulnerability
title: "CVE-2026-105133 / CVE-2026-105134, AhsayCBS backup management console: an unauthenticated authentication-bypass and code-execution chain exploited since 7 October to drop webshells and a cryptominer, with 10.3.4 also affected and no fixed release named"
headline: "Huntress: AhsayCBS flaws are exploited for SYSTEM-level code execution, and 10.3.4 is also affected"
summary: >
  Huntress observed from 2026-10-07 23:20 UTC attackers chaining two AhsayCBS flaws, CVE-2026-105133 (authentication bypass) and
  CVE-2026-105134 (code execution as SYSTEM through the Replication Receiver API), against internet-exposed servers of the backup management console that
  managed service providers and system integrators mainly use, dropping JSP webshells and an XMRig cryptominer; BleepingComputer reports at least five
  organizations targeted and a public exploit for the first flaw. Public records listed versions up to 10.3.2 as affected, but Huntress found on
  2026-10-08 that 10.3.4, which BleepingComputer calls the latest version, is also affected, and no fixed release is named, so restricting the management interface is the interim control.
discovered_at: "2026-10-10T03:51:30Z"
updated_at: null
event_date: "2026-10-07"
run_id: 2026-10-10T0255Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, rce, auth-bypass, pre-auth, actively-exploited, poc-public]
regions: [global]
sectors: [technology]
entities: ["product:ahsay-ahsaycbs"]
techniques: [T1190, T1505.003, T1059.001, T1059.003, T1569.002, T1105, T1543.003, T1036.004, T1036.005, T1564, T1057, T1124, T1071.001, T1571, T1608.001, T1496.001]
affected_products: ["Ahsay AhsayCBS"]
cves:
  - id: CVE-2026-105133
    cvss: "medium (Huntress)"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status: [exploited, poc-public, mitigation-only]
    affected: "AhsayCBS up to 10.3.2 per public records (SecurityWeek, relaying NIST); through 10.3.4 per Huntress"
    fixed: "No fixed release is named: the public records implied 10.3.4 was not affected, Huntress found 10.3.4 also affected and told Ahsay, and Ahsay's 10.3.4 release notes of 2026-08-05 list no security fix"
  - id: CVE-2026-105134
    cvss: "critical (Huntress)"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status: [exploited, poc-public, mitigation-only]
    affected: "AhsayCBS up to 10.3.2 per public records (SecurityWeek, relaying NIST); through 10.3.4 per Huntress"
    fixed: "No fixed release is named: the public records implied 10.3.4 was not affected, Huntress found 10.3.4 also affected and told Ahsay, and Ahsay's 10.3.4 release notes of 2026-08-05 list no security fix"
sources:
  - url: "https://www.huntress.com/blog/ahsaycbs-flaws-exploit"
    publisher: "Huntress"
    date: "2026-10-08"
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/"
    publisher: "BleepingComputer"
    date: "2026-10-09"
    role: corroborating
  - url: "https://www.securityweek.com/unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild/"
    publisher: "SecurityWeek"
    date: "2026-10-09"
    role: corroborating
  - url: "https://www.ahsay.com/en/support/help-centre/release-notes/cbs/v10.3.4"
    publisher: "Ahsay (AhsayCBS 10.3.4 release notes)"
    date: "2026-08-05"
    role: corroborating
closed_sources: []
evidence:
  - quote: "Starting 2026-10-07 23:20:15 UTC, Huntress observed threat actors exploiting the vulnerabilities to gain unauthenticated remote code execution and deploy webshells on exposed systems."
    publisher: "Huntress"
    source_url: "https://www.huntress.com/blog/ahsaycbs-flaws-exploit"
  - quote: "After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities."
    publisher: "Huntress"
    source_url: "https://www.huntress.com/blog/ahsaycbs-flaws-exploit"
  - quote: "Until a patch is available, we recommend restricting access to the management interface and investigating for signs of compromise."
    publisher: "Huntress"
    source_url: "https://www.huntress.com/blog/ahsaycbs-flaws-exploit"
  - quote: "The malicious activity was observed on October 7, and targeted at least five organizations."
    publisher: "BleepingComputer"
    source_url: "https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/"
verification: single-source
sourcing_note: >
  Huntress is the only observer of the exploitation and neither Ahsay nor any other party has confirmed it; BleepingComputer and SecurityWeek relay it.
  The patch position is contested: public records list versions up to 10.3.2 as affected, BleepingComputer's text reads as if 10.3.2 were the fixed version,
  Huntress found 10.3.4 affected, and Ahsay's 10.3.4 release notes list no security fix.
confidence: medium
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions:
  - "Find every AhsayCBS server your organisation or your managed-service suppliers run and put its management web interface behind a VPN or an allowlist of trusted addresses now: Huntress found 10.3.4, which BleepingComputer calls the latest version, also affected, so upgrading is not a mitigation until Ahsay names a fixed release."
  - "On any AhsayCBS server that was internet-reachable since 2026-10-04, check for the artifacts Huntress describes (children of the service downloading into Temp folders, new .jsp files in the application directory, a service that mimics the Edge updater) and re-image a host with a confirmed compromise from a trusted backup, as Huntress advises."
updates: []
migrated_from: null
---

Huntress reports that from 2026-10-07 23:20 UTC attackers exploited two flaws in AhsayCBS, the management console of Ahsay's backup software that managed service providers and system integrators mainly use, to gain unauthenticated remote code execution and deploy webshells on exposed servers ([Huntress, 2026-10-08](https://www.huntress.com/blog/ahsaycbs-flaws-exploit)). CVE-2026-105133, an improper-authentication flaw in the checkSysPwd function of the API, is used first to bypass authentication; CVE-2026-105134, in the /rps/api/json/UpdateReceivers.do endpoint of the Replication Receiver component, then gives code execution as NT AUTHORITY\SYSTEM, after which the attacker configured a malicious receiver and dropped a JSP webshell into the directory the application serves ([Huntress, 2026-10-08](https://www.huntress.com/blog/ahsaycbs-flaws-exploit)). BleepingComputer reports that the activity targeted at least five organizations on 7 October and that CVE-2026-105133 has a public exploit ([BleepingComputer, 2026-10-09](https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/)).

Follow-on activity, per Huntress: commands spawned by the AhsayCBS service process fetch payloads over HTTP from cloud object storage into a Temp folder with curl and certutil; an XMRig Monero miner renamed to look like a Microsoft Edge binary runs as SYSTEM through a service that mimics the Edge updater and a renamed copy of the NSSM service manager, and reaches its mining pool on a non-standard port; and a PowerShell script that Huntress assesses as AI-assisted checks whether Task Manager is running, uses the host's local time to decide when to close it, and stops the miner while it is open ([Huntress, 2026-10-08](https://www.huntress.com/blog/ahsaycbs-flaws-exploit)). The patch position is contested: public records listed AhsayCBS up to 10.3.2 as affected ([SecurityWeek, 2026-10-09](https://www.securityweek.com/unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild/)), while Huntress's update of 2026-10-08 says 10.3.4 is also affected, that it has told Ahsay, and that owners should restrict the management interface until a patch is available ([Huntress, 2026-10-08](https://www.huntress.com/blog/ahsaycbs-flaws-exploit)), and BleepingComputer calls 10.3.4 the latest version ([BleepingComputer, 2026-10-09](https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/)); Ahsay's release notes for 10.3.4 list no security fix ([Ahsay, 2026-08-05](https://www.ahsay.com/en/support/help-centre/release-notes/cbs/v10.3.4)).

**Exposure:** AhsayCBS servers, a Windows service run from cbssvcX64.exe or cbssvcX86.exe, whose management web interface is reachable from untrusted networks, in every version through 10.3.4 according to Huntress ([Huntress, 2026-10-08](https://www.huntress.com/blog/ahsaycbs-flaws-exploit)).

**Detection:** process-creation telemetry with parent lineage: children of the AhsayCBS service process outside its normal startup and maintenance commands, because commands from an uploaded JSP webshell appear as direct children of the service, and curl or certutil from that lineage writing into a Temp folder; service inventory: a service named like the Edge update service running an Edge-named binary from a Temp folder as SYSTEM; PowerShell script-block logs: a script that checks for Task Manager and stops or starts a service to match; command lines that name WinRing0 next to a URL; and new .jsp files in the application directory. Huntress published four Sigma rules ([Huntress, 2026-10-08](https://www.huntress.com/blog/ahsaycbs-flaws-exploit)).

**Triage:** AhsayCBS legitimately spawns its own startup and maintenance commands, so a child process alone is weak; the discriminators Huntress gives are a child of the service that downloads files into a Temp folder, and an Edge-named binary run as SYSTEM from a Temp folder under a service that mimics the Edge updater ([Huntress, 2026-10-08](https://www.huntress.com/blog/ahsaycbs-flaws-exploit)).

**Defender takeaway:** restrict the AhsayCBS management interface to trusted addresses or a VPN now and ask your backup suppliers whether they run it, because the exploit targets the externally reachable web application and no fixed release is named ([Huntress, 2026-10-08](https://www.huntress.com/blog/ahsaycbs-flaws-exploit)); where an indicator of compromise turns up, re-image the host from a trusted backup, since Huntress says attackers hid secondary backdoors for extended persistence ([Huntress, 2026-10-08](https://www.huntress.com/blog/ahsaycbs-flaws-exploit)).
