Unpatched AhsayCBS flaws exploited to deploy webshells and crypto miners
TLDR
- Threat actors are chaining two unpatched flaws in the AhsayCBS backup management platform, used by managed service providers and system integrators, to bypass authentication and run arbitrary commands.12
- Huntress observed exploitation beginning 7 October against at least five organisations, with attackers deploying Java webshells and an XMRig cryptocurrency miner disguised as Microsoft Edge.12
- Both CVE-2026-105133 (authentication bypass) and CVE-2026-105134 (OS command injection) are listed as fixed in AhsayCBS 10.3.2, but Huntress found the current latest version, 10.3.4, is also vulnerable, making them zero-days in practice.12
- The miner hides via a PowerShell script suspected to be AI-assisted, which stops mining when Task Manager opens and forcibly closes Task Manager at 6pm or after an hour left open overnight.12
AhsayCBS is typically deployed by MSPs and system integrators to manage backups across client environments.1 The attacker chains CVE-2026-105133, an improper-authentication flaw in the platform's checkSysPwd() function (CVSS v4 5.5), with CVE-2026-105134, an OS command-injection vulnerability in the Replication Receiver component (CVSS v4 9.3), to bypass login and achieve remote code execution.12 CVE identifiers for the pair were not published until 4 October 2026, and Huntress says exploitation began just three days later, at 11:20pm UTC on 7 October.2
After gaining access, the attacker performs reconnaissance, drops JSP webshells, and downloads an XMRig miner saved as "edge.exe" to impersonate the Microsoft Edge browser; it persists via a service called "MicrosoftEdgeUpdateSvc" built on a modified copy of the legitimate NSSM (Non-Sucking Service Manager) utility.1 A PowerShell script named Taskgmr.ps1, which Huntress believes was written with AI assistance, conceals the mining activity by halting the service whenever Task Manager is opened and restarting it once Task Manager closes, and separately kills Task Manager at 6pm local time or if it has been open for more than an hour overnight.12 In one incident, the attacker also deployed the legitimate but vulnerable WinRing0x64.sys driver via certutil.exe, likely to gain kernel-level hardware access and boost mining performance.12
Although NVD advisories state the issues were addressed in AhsayCBS 10.3.4, Huntress says that version remains affected, effectively turning the pair into zero-days despite the vendor's fix claim.12 BleepingComputer says it contacted AhsayCBS about patch plans but had not heard back as of publication.1 Pending a fix, Huntress recommends restricting access to the AhsayCBS management interface to trusted IP addresses or a VPN, and says any confirmed compromise should be treated as requiring a full restore from a safe backup, since the attacker may have planted further backdoors for persistence.12
Why it matters: backup-management platforms sit at the centre of an MSP's client relationships with privileged access across every environment they touch, so a vendor's "fixed" claim turning out to be wrong, with zero-day exploitation already under way against five organisations, leaves defenders with no patch to apply and only network-level isolation to fall back on.