Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
Huntress saw attackers chain two AhsayCBS flaws for SYSTEM RCE, webshells, and XMRig mining.
Huntress observed threat actors chaining two AhsayCBS flaws from 7 October 2026 to gain unauthenticated remote code execution as NT AUTHORITY\SYSTEM. Medium CVE-2026-105133 bypasses authentication in checkSysPwd, and critical CVE-2026-105134 in the Replication Receiver UpdateReceivers.do API enables code execution. Actors dropped JSP webshells and an XMRig miner masquerading as Microsoft Edge, persisted it with a fake MicrosoftEdgeUpdateSvc service and modified NSSM, and in one case loaded vulnerable WinRing0x64.sys. Huntress later found AhsayCBS 10.3.4 is affected and advises restricting the management interface until a patch is available.