Unpatched AhsayCBS Flaws Exploited to Install Webshells and Cryptocurrency Miners

Summary
Attackers exploited two AhsayCBS flaws to deploy JSP webshells and an XMRig miner at five or more organizations. Huntress says the latest version, 10.3.4, is also affected; it recommends restricting management access and investigating for compromise.
Key points
- Attacks observed October 7 targeted at least five organizations using AhsayCBS, a backup management platform used by MSPs and system integrators.
- CVE-2026-105133 enables authentication bypass; CVE-2026-105134 can enable OS command injection. Attackers chained the flaws for access and code execution.
- Although both flaws were reported fixed in version 10.3.2, Huntress found that Ahsay 10.3.4, the latest version, is also affected.
- Attackers performed reconnaissance, deployed JSP webshells, and installed XMRig disguised as edge.exe, with persistence through a service named MicrosoftEdgeUpdateSvc.
- A PowerShell script concealed mining activity by stopping the service when Task Manager was open and restarting it afterward.
- Huntress provided indicators of compromise and four Sigma rules. Until a patch is available, it recommends limiting management-interface access to trusted IPs and investigating for compromise.
- For confirmed compromise, administrators should restore the host from a safe backup because additional backdoors may provide persistent access.
Article Details
- Vulnerability Types
- Authentication bypass
- OS command injection
- Severity
- One critical-severity and one medium-severity vulnerability; the article does not map individual severity levels to the CVEs.
- Affected Versions
- AhsayCBS 10.3.4 is reported by Huntress as affected; the article says both vulnerabilities are reported as fixed in AhsayCBS 10.3.2.
- Exploitation Status
- active
- Exploit Availability
- public_exploit
- Patch Status
- unavailable
- Workarounds
- Restrict access to the AhsayCBS management interface to trusted IP addresses only.
MITRE ATT&CK
T1059.001 · PowerShellA PowerShell script named Taskgmr.ps1 stopped and restarted the miner's service based on Task Manager activity.T1105 · Ingress Tool TransferThe attacker downloaded the XMRig miner after gaining access.T1505.003 · Web ShellThe attacker deployed Java Server Page (JSP) webshells after gaining access.
CVE
CVE-2026-105133The two security issues exploited in attacks are tracked as CVE-2026-105133, an authentication bypass vulnerability that has a public exploit, and CVE-2026-105134, which can be leveraged for OS command injection.CVE-2026-105134The two security issues exploited in attacks are tracked as CVE-2026-105133, an authentication bypass vulnerability that has a public exploit, and CVE-2026-105134, which can be leveraged for OS command injection.