Two AhsayCBS Zero-Day Vulnerabilities Actively Exploited to Take Over Backup Servers
Attackers are exploiting two AhsayCBS zero-days for unauthenticated SYSTEM access on exposed backup servers.
Field Effect reported that attackers began exploiting two Ahsay Cloud Backup Server zero-days on October 7, 2026. CVE-2026-105133 is improper authentication in checkSysPwd (CVSS 5.5), and CVE-2026-105134 is OS command injection in the Replication Receiver (CVSS 9.3). Chained, they let unauthenticated attackers configure a malicious receiver, deploy a JSP web shell, and execute as NT AUTHORITY\SYSTEM. Observed intrusions installed XMRig miners disguised as Microsoft Edge, a fake Edge update service, and PowerShell concealment scripts; five organizations were identified on the first reporting day. Versions through 10.3.4 were vulnerable.