HomeCybersecurityAhsayCBS Backup-Server Flaws Exploited to Plant Webshells and Cryptominers, Huntress Reports

AhsayCBS Backup-Server Flaws Exploited to Plant Webshells and Cryptominers, Huntress Reports

Security firm Huntress says attackers have been exploiting two flaws in AhsayCBS, backup-server software from Ahsay, since 7 October. Huntress says the latest version, 10.3.4, is affected. Ahsay says 10.3.4 fixes both flaws. The sources disagree, and TSN cannot settle it.

What AhsayCBS is

Ahsay describes AhsayCBS as server software with “a web based central management console for system administrator to easily manage the whole backup system, as well as all AhsayOBM / AhsayACB backup users and their backup data” [4]. Huntress says it is “primarily used by managed service providers (MSPs) and system integrators”, meaning firms that run IT for other businesses [2].

What Huntress reports

Reported (Huntress, relayed by BleepingComputer). The flaws are CVE-2026-105133, a medium-severity improper-authentication bug, and CVE-2026-105134, a critical bug in the Replication Receiver component that Huntress says allows “unauthenticated remote code execution” with the highest Windows privileges [2]. The public CVE records say exploits for both are public [5]. Huntress says attackers chain them, bypassing login first, then running code [2].

Huntress dates the first exploitation to 23:20 UTC on 7 October and says it had seen “five organizations” targeted by 8 October [2]. BleepingComputer writes “at least five” [1].

Afterwards, Huntress says, attackers scouted the system, planted webshells (small scripts on a web server that let an attacker run commands remotely) and installed XMRig, an open-source cryptominer, named “edge.exe” to look like Microsoft Edge [2]. A miner uses the victim’s computer to earn cryptocurrency for someone else. Huntress names no actor, and neither does TSN.

Which version is fixed?

  • BleepingComputer: both flaws “reported as fixed in AhsayCBS 10.3.2” [1].
  • CVE records: 10.3.2 and earlier affected; 10.3.4 unaffected [5].
  • Ahsay, 9 October: both “were addressed in AhsayCBS v10.3.4.0, released on 4 August 2026”; upgraded partners “are no longer affected” [3].
  • Huntress, 8 October update: “Ahsay 10.3.4 is also affected” [2].

Ahsay’s release notes for 10.3.2 and 10.3.4 do not name the CVEs [6].

What the sources recommend

Huntress says to limit access to the management interface to trusted IP addresses or require a VPN, and, if any indicators of compromise (traces left by the attack) are found, to re-image the host from a trusted backup, because attackers can hide secondary backdoors [2]. It has published indicators and four Sigma rules, shareable detection rules [2]. Ahsay says an upgrade does not fix an earlier compromise and recommends engaging qualified cybersecurity professionals [3].

CISA’s catalogue

On 10 October TSN read CISA’s Known Exploited Vulnerabilities catalogue, version 2026.10.08. Neither CVE is listed [7].

The Bottom Line

Huntress reports real-world attacks using two AhsayCBS flaws, and says version 10.3.4 is still vulnerable. Ahsay says 10.3.4 fixes them. Until one side shows evidence, treat the version question as disputed. Huntress’s observed victim count is five.

Sources

  1. Bill Toulas, “Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto”, BleepingComputer, 9 October 2026 (trade press; relays Huntress). https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/
  2. Dray Agha, “Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer”, Huntress, 8 October 2026, with update of 8 October 6 p.m. ET (security vendor’s own research; telemetry not independently verified). https://www.huntress.com/blog/ahsaycbs-flaws-exploit
  3. Ahsay, “Clarification on AhsayCBS v10.3.4.0 vulnerabilities”, 9 October 2026 (vendor statement). https://www.ahsay.com/en/company/announcements/clarification-v10.3.4.0-cve
  4. Ahsay, “Centralized Management Console’s Features”, read 10 October 2026 (vendor’s own description). https://portal.ahsay.com/jsp/en/products/ahsay-products_backup-software_features_console.jsp
  5. CVE Program records CVE-2026-105133 and CVE-2026-105134, published 4 October 2026 by VulDB, read 10 October 2026. https://www.cve.org/CVERecord?id=CVE-2026-105133 and https://www.cve.org/CVERecord?id=CVE-2026-105134
  6. Ahsay, AhsayCBS release notes v10.3.2 (20 July 2026) and v10.3.4 (5 August 2026), read 10 October 2026. https://www.ahsay.com/en/support/help-centre/release-notes/cbs/v10.3.2 and https://www.ahsay.com/en/support/help-centre/release-notes/cbs/v10.3.4
  7. CISA, Known Exploited Vulnerabilities Catalog, catalogue version 2026.10.08, read 10 October 2026. https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Share this story

More in this category

Latest on TSN

Free TSN tools: crypto calculator, Flux dashboard and more.