Unpatched AhsayCBS Flaws Exploited to Install Webshells and Cryptocurrency Miners

· Original article ↗

Summary

Attackers exploited two AhsayCBS flaws to deploy JSP webshells and an XMRig miner at five or more organizations. Huntress says the latest version, 10.3.4, is also affected; it recommends restricting management access and investigating for compromise.

Key points

  • Attacks observed October 7 targeted at least five organizations using AhsayCBS, a backup management platform used by MSPs and system integrators.
  • CVE-2026-105133 enables authentication bypass; CVE-2026-105134 can enable OS command injection. Attackers chained the flaws for access and code execution.
  • Although both flaws were reported fixed in version 10.3.2, Huntress found that Ahsay 10.3.4, the latest version, is also affected.
  • Attackers performed reconnaissance, deployed JSP webshells, and installed XMRig disguised as edge.exe, with persistence through a service named MicrosoftEdgeUpdateSvc.
  • A PowerShell script concealed mining activity by stopping the service when Task Manager was open and restarting it afterward.
  • Huntress provided indicators of compromise and four Sigma rules. Until a patch is available, it recommends limiting management-interface access to trusted IPs and investigating for compromise.
  • For confirmed compromise, administrators should restore the host from a safe backup because additional backdoors may provide persistent access.

Article Details

Vulnerability Types
  • Authentication bypass
  • OS command injection
Severity
One critical-severity and one medium-severity vulnerability; the article does not map individual severity levels to the CVEs.
Affected Versions
  • AhsayCBS 10.3.4 is reported by Huntress as affected; the article says both vulnerabilities are reported as fixed in AhsayCBS 10.3.2.
Exploitation Status
active
Exploit Availability
public_exploit
Patch Status
unavailable
Workarounds
  • Restrict access to the AhsayCBS management interface to trusted IP addresses only.

MITRE ATT&CK

CVE

Malware

Products

Tools

Industries

Related Articles