Unpatched AhsayCBS Vulnerabilities Exploited in the Wild, Leading to RCE
Two critical vulnerabilities in AhsayCBS, CVE-2026-105133 and CVE-2026-105134, are being actively exploited by threat actors to achieve unauthenticated remote code execution.

Threat actors are actively exploiting two critical, unpatched vulnerabilities in the AhsayCBS backup solution, enabling them to achieve remote code execution (RCE) on vulnerable systems. The vulnerabilities, tracked as CVE-2026-105133 and CVE-2026-105134, were disclosed on October 4th, with NIST warning that exploit code was already available. AhsayCBS is a centralized cloud backup server management console widely used by Managed Service Providers (MSPs) and system integrators.
The flaws allow attackers to bypass authentication mechanisms by manipulating arguments in specific functions within the AhsayCBS tool. This bypass then permits the injection of arbitrary operating system commands, leading to a full compromise of the affected server. Cybersecurity firm Huntress has confirmed that these vulnerabilities are being exploited in the wild, and notably, the latest version of AhsayCBS, 10.3.4, is also affected, indicating that a patch has not yet been deployed or is ineffective against these specific exploits.
Huntress observed threat actors chaining these two vulnerabilities to gain unauthenticated RCE and subsequently deploy webshells on exposed systems. In one instance, CVE-2026-105134 was exploited for RCE with System privileges through an API within the Replication Receiver component. This API contained an authentication bypass that allowed a malicious token to substitute valid credentials, enabling the attacker to configure a malicious receiver and drop a Java Server Page (JSP) webshell into the application directory.
Following initial access, attackers conducted reconnaissance and deployed XMRig cryptominers, disguised as Microsoft Edge processes. To maintain persistence and evade detection, they employed an AI-assisted PowerShell script designed to monitor and terminate the Task Manager if it remained open. Further persistence was established by creating a Windows service that masqueraded as Microsoft Edge Update, using a modified version of the legitimate NSSM utility named msedge.exe to execute with System privileges.
In at least one observed attack, the threat actors utilized WinRing0x64.sys, a legitimate but vulnerable kernel driver, to grant the cryptocurrency miner kernel-level access. This allowed the miner to operate with elevated privileges, enhancing its effectiveness and stealth. The attackers' tactics highlight a sophisticated approach, combining vulnerability exploitation with advanced techniques for persistence and evasion.
As of October 8th, Huntress reported that at least five organizations had been targeted by these exploits. The firm strongly recommends that organizations restrict access to the AhsayCBS management interface. Access should be limited to trusted IP addresses only or require a VPN connection to mitigate the risk of external exploitation. Organizations are also advised to investigate their systems for any signs of compromise, including the presence of webshells or unusual processes.
Given the active exploitation and the fact that the latest version is affected, prompt action is crucial for organizations relying on AhsayCBS. The lack of a timely patch exacerbates the risk, making network segmentation and strict access controls paramount. The ongoing exploitation underscores the importance of continuous monitoring and rapid response to emerging threats, especially for critical infrastructure like backup solutions.