Huntress: AhsayCBS bugs CVE-2026-105133 and CVE-2026-105134 exploited to drop web shells and XMRig miners

Huntress reports attackers chaining AhsayCBS flaws CVE-2026-105133 and CVE-2026-105134 to deploy web shells and XMRig miners. Learn details.

Huntress: AhsayCBS bugs CVE-2026-105133 and CVE-2026-105134 exploited to drop web shells and XMRig miners
Vulnerabilities

Illustrative image generated with AI

Attackers are exploiting two flaws in Ahsay's AhsayCBS backup software, CVE-2026-105133 and CVE-2026-105134, to take control of hosts, according to Huntress. The findings were relayed by The Hacker News. Huntress says exploitation began at 11:20 p.m. UTC on October 7, 2026. It estimates that five targeted organizations were affected as of October 8. Intruders reportedly installed web shells and XMRig cryptocurrency miners.

Two flaws that can lead to command execution

The reporting says a remote attacker could chain the two bugs: one bypasses authentication, the other runs arbitrary commands. The NVD records describe each flaw on its own.

  • CVE-2026-105133 is an improper authentication weakness (CWE-287) in the checkSysPwd function of com/ahsay/obs/api/ApiStructsAction.java, part of the API component. Tampering with the random argument triggers it over the network. VulDB, the CNA, scores it 5.5 under CVSS 4.0. A CVSS 3.1 score of 7.3 is also recorded (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
  • CVE-2026-105134 is an OS command injection (CWE-77, CWE-78) in the Replication Receiver component, at /rps/api/json/UpdateReceivers.do. It also involves the random argument and can be reached remotely. VulDB rates it 9.3 critical under CVSS 4.0. Its CVSS 3.1 score is 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).

Both NVD pages (CVE-2026-105133, CVE-2026-105134) say an exploit is public and "may be used." NVD published the records on October 4, 2026, and last modified them on October 6. It has not yet added its own assessment; both entries are marked "Not Scheduled" for enrichment.

Versions and the 10.3.4 question

VulDB lists AhsayCBS 10.3.0, 10.3.1 and 10.3.2 as affected and 10.3.4 as unaffected. NVD says upgrading to 10.3.4 mitigates both issues.

The Hacker News describes a complication. After noting that the NVD advisories say the problems were addressed in 10.3.4, it adds that Huntress "has since revealed that it's also impacted." The outlet says this effectively makes them zero-days. The sentence does not spell out what "it" covers beyond that context, so whether 10.3.4 protects against the attacks seen is unresolved in the available reporting. The same article says that, absent a patch, users should limit access to the management interface and hunt for compromise.

What happened after access

Huntress's account of post-exploitation activity, as relayed by The Hacker News, runs as follows:

  • Attackers reached the host through the externally accessible AhsayCBS web application service. They then carried out reconnaissance and dropped web shells.
  • XMRig miners were disguised as the Microsoft Edge browser under the file name edge.exe.
  • A PowerShell script, Taskgmr.ps1, was launched via curl to support the mining. It stops mining as soon as Windows Task Manager is opened. It is also configured to terminate Task Manager at 6 p.m. if Task Manager has been left open for more than one hour overnight. The reporting gives no time zone for that trigger. Huntress suspects an AI tool helped write the script; that remains a suspicion.
  • In at least one incident, the built-in certutil.exe was used to fetch WinRing0x64.sys into the TEMP folder. The driver is legitimate but vulnerable. The Hacker News says it was likely downloaded to gain kernel-level access to the hardware and tune the mining.

What administrators can do

Huntress advises restricting web access to the AhsayCBS management interface, since the exploit targets the externally reachable web application service. In its words, access "should be limited to trusted IP addresses only or require VPN."

NVD's guidance is to upgrade to AhsayCBS 10.3.4, and the 10.3.4 release notes are listed among the NVD references. Given the conflicting statements about that version, restricting the management interface is sensible either way. Teams checking AhsayCBS hosts can look for edge.exe, Taskgmr.ps1, a WinRing0x64.sys file in TEMP, and certutil.exe or curl downloads.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →