Attackers are exploiting two flaws in Ahsay's AhsayCBS backup software, CVE-2026-105133 and CVE-2026-105134, to take control of hosts, according to Huntress. The findings were relayed by The Hacker News. Huntress says exploitation began at 11:20 p.m. UTC on October 7, 2026. It estimates that five targeted organizations were affected as of October 8. Intruders reportedly installed web shells and XMRig cryptocurrency miners.
Two flaws that can lead to command execution
The reporting says a remote attacker could chain the two bugs: one bypasses authentication, the other runs arbitrary commands. The NVD records describe each flaw on its own.
- CVE-2026-105133 is an improper authentication weakness (CWE-287) in the
checkSysPwdfunction ofcom/ahsay/obs/api/ApiStructsAction.java, part of the API component. Tampering with therandomargument triggers it over the network. VulDB, the CNA, scores it 5.5 under CVSS 4.0. A CVSS 3.1 score of 7.3 is also recorded (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L). - CVE-2026-105134 is an OS command injection (CWE-77, CWE-78) in the Replication Receiver component, at
/rps/api/json/UpdateReceivers.do. It also involves therandomargument and can be reached remotely. VulDB rates it 9.3 critical under CVSS 4.0. Its CVSS 3.1 score is 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Both NVD pages (CVE-2026-105133, CVE-2026-105134) say an exploit is public and "may be used." NVD published the records on October 4, 2026, and last modified them on October 6. It has not yet added its own assessment; both entries are marked "Not Scheduled" for enrichment.
Versions and the 10.3.4 question
VulDB lists AhsayCBS 10.3.0, 10.3.1 and 10.3.2 as affected and 10.3.4 as unaffected. NVD says upgrading to 10.3.4 mitigates both issues.
The Hacker News describes a complication. After noting that the NVD advisories say the problems were addressed in 10.3.4, it adds that Huntress "has since revealed that it's also impacted." The outlet says this effectively makes them zero-days. The sentence does not spell out what "it" covers beyond that context, so whether 10.3.4 protects against the attacks seen is unresolved in the available reporting. The same article says that, absent a patch, users should limit access to the management interface and hunt for compromise.
What happened after access
Huntress's account of post-exploitation activity, as relayed by The Hacker News, runs as follows:
- Attackers reached the host through the externally accessible AhsayCBS web application service. They then carried out reconnaissance and dropped web shells.
- XMRig miners were disguised as the Microsoft Edge browser under the file name
edge.exe. - A PowerShell script,
Taskgmr.ps1, was launched viacurlto support the mining. It stops mining as soon as Windows Task Manager is opened. It is also configured to terminate Task Manager at 6 p.m. if Task Manager has been left open for more than one hour overnight. The reporting gives no time zone for that trigger. Huntress suspects an AI tool helped write the script; that remains a suspicion. - In at least one incident, the built-in
certutil.exewas used to fetchWinRing0x64.sysinto the TEMP folder. The driver is legitimate but vulnerable. The Hacker News says it was likely downloaded to gain kernel-level access to the hardware and tune the mining.
What administrators can do
Huntress advises restricting web access to the AhsayCBS management interface, since the exploit targets the externally reachable web application service. In its words, access "should be limited to trusted IP addresses only or require VPN."
NVD's guidance is to upgrade to AhsayCBS 10.3.4, and the 10.3.4 release notes are listed among the NVD references. Given the conflicting statements about that version, restricting the management interface is sensible either way. Teams checking AhsayCBS hosts can look for edge.exe, Taskgmr.ps1, a WinRing0x64.sys file in TEMP, and certutil.exe or curl downloads.




