Skip to content
feed: live
0dayNews
cloud

AhsayCBS Backup Platform Exploited, No Patch Ready

Two AhsayCBS flaws, including a CVSS 10.0 auth bypass, are chained to drop webshells and XMRig miners on MSP networks. No patch is available.

AhsayCBS Backup Platform Exploited, No Patch Ready
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

Attackers are chaining two unpatched flaws in the AhsayCBS backup management console to drop webshells and XMRig cryptocurrency miners on targeted systems. Huntress researchers confirmed active exploitation against at least five organizations as of October 7, 2026. No patch is available from Ahsay Systems.

The vulnerabilities

CVE-2026-105134 is a CVSS 10.0 critical authentication bypass in AhsayCBS. The flaw lets an unauthenticated attacker substitute a random token for valid credentials, gaining access to the management console without a password.

CVE-2026-105133 is a CVSS 7.3 high OS command injection. Once inside the console, an attacker can manipulate function arguments to execute arbitrary commands with SYSTEM-level privileges.

Chained together, the two flaws give an unauthenticated remote attacker full control of the host. NIST noted publicly released exploit code as of October 4, 2026, the same day Huntress disclosed the findings.

Affected versions include 10.3.4 (the current release) and all earlier versions. Huntress notes the vulnerabilities were initially thought fixed in 10.3.2 but confirmed present in 10.3.4 as well.

What attackers are deploying

Huntress observed the following in compromised environments, per their research:

  • JSP webshells for persistent access to the management console
  • XMRig miners disguised as edge.exe, registered as MicrosoftEdgeUpdateSvc for persistence
  • WinRing0x64.sys, a vulnerable-but-legitimate driver used to access hardware for the mining operation
  • taskgmr.ps1, a PowerShell script that conceals the mining process from plain view

The targeting is not random. AhsayCBS is used primarily by managed service providers and system integrators to manage backup jobs across multiple client environments. A compromised backup console typically holds credentials, network access, and stored data for every client under management.

What to do right now

Ahsay Systems has not issued a patch. BleepingComputer’s attempts to reach the vendor went unanswered as of October 9.

Until a fix ships:

  1. Restrict the AhsayCBS management interface to trusted IP addresses only. Block any external access at the perimeter.
  2. Search for compromise indicators: edge.exe in unusual paths, the MicrosoftEdgeUpdateSvc service, WinRing0x64.sys, and taskgmr.ps1.
  3. If you find signs of intrusion, restore from clean backups sourced from before the compromise window. Do not trust a backdoored backup server to recover itself.

This one sits high on the priority list. The CVSS 10.0 auth bypass requires no credentials, public exploit code is already out, and attackers are actively using it against MSP infrastructure.

MSPs running similar management platforms have been targeted with auth-bypass chains before: the Fleet MDM auth bypass (CVE-2026-103264) and Perforce P4 Search RCE (CVE-2026-100102) followed a similar pattern this month.

Related CVEs
  • [ CRITICAL ]CVE-2026-105134Authentication bypass in AhsayCBS backup management console
  • [ HIGH ]CVE-2026-105133OS command injection in AhsayCBS backup management console

Found this useful? Share it.