AhsayCBS Backup Platform Exploited, No Patch Ready
Two AhsayCBS flaws, including a CVSS 10.0 auth bypass, are chained to drop webshells and XMRig miners on MSP networks. No patch is available.

Attackers are chaining two unpatched flaws in the AhsayCBS backup management console to drop webshells and XMRig cryptocurrency miners on targeted systems. Huntress researchers confirmed active exploitation against at least five organizations as of October 7, 2026. No patch is available from Ahsay Systems.
The vulnerabilities
CVE-2026-105134 is a CVSS 10.0 critical authentication bypass in AhsayCBS. The flaw lets an unauthenticated attacker substitute a random token for valid credentials, gaining access to the management console without a password.
CVE-2026-105133 is a CVSS 7.3 high OS command injection. Once inside the console, an attacker can manipulate function arguments to execute arbitrary commands with SYSTEM-level privileges.
Chained together, the two flaws give an unauthenticated remote attacker full control of the host. NIST noted publicly released exploit code as of October 4, 2026, the same day Huntress disclosed the findings.
Affected versions include 10.3.4 (the current release) and all earlier versions. Huntress notes the vulnerabilities were initially thought fixed in 10.3.2 but confirmed present in 10.3.4 as well.
What attackers are deploying
Huntress observed the following in compromised environments, per their research:
- JSP webshells for persistent access to the management console
- XMRig miners disguised as
edge.exe, registered asMicrosoftEdgeUpdateSvcfor persistence WinRing0x64.sys, a vulnerable-but-legitimate driver used to access hardware for the mining operationtaskgmr.ps1, a PowerShell script that conceals the mining process from plain view
The targeting is not random. AhsayCBS is used primarily by managed service providers and system integrators to manage backup jobs across multiple client environments. A compromised backup console typically holds credentials, network access, and stored data for every client under management.
What to do right now
Ahsay Systems has not issued a patch. BleepingComputer’s attempts to reach the vendor went unanswered as of October 9.
Until a fix ships:
- Restrict the AhsayCBS management interface to trusted IP addresses only. Block any external access at the perimeter.
- Search for compromise indicators:
edge.exein unusual paths, theMicrosoftEdgeUpdateSvcservice,WinRing0x64.sys, andtaskgmr.ps1. - If you find signs of intrusion, restore from clean backups sourced from before the compromise window. Do not trust a backdoored backup server to recover itself.
This one sits high on the priority list. The CVSS 10.0 auth bypass requires no credentials, public exploit code is already out, and attackers are actively using it against MSP infrastructure.
MSPs running similar management platforms have been targeted with auth-bypass chains before: the Fleet MDM auth bypass (CVE-2026-103264) and Perforce P4 Search RCE (CVE-2026-100102) followed a similar pattern this month.
- [ CRITICAL ]CVE-2026-105134Authentication bypass in AhsayCBS backup management console
- [ HIGH ]CVE-2026-105133OS command injection in AhsayCBS backup management console
Found this useful? Share it.


