Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Huntress has confirmed active exploitation of two zero-day vulnerabilities in AhsayCBS starting at 23:20:15 UTC on October 7, 2026. At least five organizations were compromised by October 8, 2026. Version 10.3.4, designated as the fix by the vendor, has been verified as still vulnerable, leaving backup infrastructure without effective defense.
- CVE-2026-105133 (CVSS 6.9, auth bypass) and CVE-2026-105134 (CVSS 10.0, RCE) are chained for unauthenticated remote code execution with SYSTEM privileges.
- In-the-wild exploitation began October 7, 2026; by October 8 Huntress had detected at least five targeted organizations.
- Post-exploitation includes JSP webshells, XMRig cryptominer disguised as msedge.exe, persistence via NSSM, and the vulnerable WinRing0x64.sys kernel driver.
- Version 10.3.4, listed as the fix in the NVD record, remains vulnerable according to direct verification by Huntress.
The Attack Chain: From Fake Token to System Shell
Attackers chain two flaws in the AhsayCBS Replication Receiver component. CVE-2026-105133, classified as Improper Authentication with CVSS 6.9, allows valid credentials to be replaced with a random token. Per Huntress' reconstruction reported by SecurityWeek, "The API contains an authentication bypass that could allow for a random token to substitute valid credentials." This bypass opens access to the /rps/api/json/UpdateReceivers.do endpoint.
From there, CVE-2026-105134 triggers via the unsanitized 'random' parameter. The flaw is an OS command injection that allows arbitrary command execution with the backup service's privileges. The AhsayCBS service runs as NT AUTHORITY/SYSTEM, so the injection translates immediately into RCE with maximum OS privileges. SecurityOnline.info assigns the vulnerability a CVSS 4.0 score of 10.0 Critical; the NVD record confirms the full vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P.
TheHackerWire adds technical details on the precise injection mechanism but with a reference date prior to the confirmed exploitation and without verification of in-the-wild activity. Huntress observed this chain executing actively on production systems, confirming the two vulnerabilities are chained for access to target systems.
From Webshell to Miner: Post-Exploitation Anatomy
Huntress observed threat actors exploiting the vulnerabilities for "unauthenticated remote code execution and deploy webshells on exposed systems." Deployment is not an end in itself: once a foothold is established, operators install a JSP webshell in the application root directory, gaining persistent access via web interface.
The second phase of compromise includes downloading XMRig, a Monero cryptominer, disguised under the name msedge.exe to blend in with the Microsoft Edge browser. Persistence is achieved via NSSM (Non-Sucking Service Manager), renamed to evade detection. A PowerShell script monitors and terminates Task Manager instances, preventing manual inspection of running processes.
The miner gains kernel-level access through the vulnerable WinRing0x64.sys driver. The brief identifies it as a vulnerable kernel driver for kernel-level access by the miner. Huntress has not documented further details on this driver's capabilities beyond this specific role.
"Until a patch is available, we recommend restricting access to the management interface and investigating for signs of compromise" — Huntress (via SecurityWeek)
The Patch Black Hole: When the Fix Doesn't Fix
The NVD record for CVE-2026-105134 lists affected versions 10.3.0-10.3.2 and a fix in version 10.3.4. This indication is misaligned with field verification. Huntress tested 10.3.4 and confirmed the version remains vulnerable to exploitation. The disconnect between the official advisory and operational reality is the critical point of this entire episode: organizations that updated promptly still found themselves exposed.
The context is particularly sensitive. AhsayCBS is a centralized backup platform used by MSPs and system integrators to manage data protection for entire client fleets. The backup server, traditionally considered a recovery asset, becomes a primary attack vector here. A SYSTEM-level compromise on the backup node exposes the local host. Huntress has not confirmed extended access to managed backup repositories: potential access to backup data beyond cryptomining and persistence remains unverified.
Immediate Actions
Restrict management interface access: Huntress explicitly recommends limiting reachability of the management interface, reducing the surface exposed to the internet.
Hunt for compromise indicators: Investigate for unauthorized JSP files in the application root, Windows services with masked names, and msedge.exe processes running on servers without a browser.
Inspect kernel driver: Check for the presence of the WinRing0x64.sys driver as an indicator of cryptojacking with documented privilege escalation by Huntress.
Monitor exploitation: SecurityOnline.info reports Task Manager hiding techniques; security teams should correlate process anomalies with the known exploitation timeline.
Sources and Limitations
Information is based on Huntress research reported by SecurityWeek and SecurityOnline.info. TheHackerWire provides technical details on the injection mechanism but with a date prior to confirmed exploitation. The NVD record for CVE-2026-105133 lacks technical exploit details; the record for CVE-2026-105134 indicates a 10.3.4 fix contested by primary sources. No effective patch release date is available from Ahsay Systems. Threat actor identity is not attributed to a specific group.
Sources: SecurityWeek; SecurityOnline.info; TheHackerWire; NVD (CVE-2026-105133, CVE-2026-105134)
Information has been verified against cited sources and is current as of publication.
Sources
- https://www.securityweek.com/unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild/
- https://securityonline.info/ahsaycbs-vulnerabilities-exploited/
- https://www.thehackerwire.com/cve-2026-105134-a-flaw-has-been-found-in-ahsay-ahsaycbs-up-to-10/
- https://nvd.nist.gov/vuln/detail/cve-2026-105133
- https://nvd.nist.gov/vuln/detail/cve-2026-105134
- https://podcast.securityweek.com/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.