Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Huntress says attackers are exploiting unpatched AhsayCBS flaws for unauthenticated RCE, webshells, and cryptominers.
Huntress says attackers are chaining two unpatched AhsayCBS flaws, CVE-2026-105133 and CVE-2026-105134, for unauthenticated remote code execution. NIST disclosed them on October 4 with public exploit code; versions through 10.3.4 remain affected. By October 8 at least five organizations were hit, with JSP webshells, XMRig miners disguised as Microsoft Edge, PowerShell monitoring, and persistence via a fake Edge Update service using NSSM. One case also loaded the vulnerable WinRing0x64.sys driver. Huntress advises restricting the management interface to trusted IPs or a VPN until a patch exists.