Two AhsayCBS Zero-Day Vulnerabilities Actively Exploited to Take Over Backup Servers
Attackers are exploiting two AhsayCBS zero-days for unauthenticated SYSTEM access on exposed backup servers.
Field Effect reported that attackers began exploiting two Ahsay Cloud Backup Server zero-days on October 7, 2026. CVE-2026-105133 is improper authentication in checkSysPwd (CVSS 5.5), and CVE-2026-105134 is OS command injection in the Replication Receiver (CVSS 9.3). Chained, they let unauthenticated attackers configure a malicious receiver, deploy a JSP web shell, and execute as NT AUTHORITY\SYSTEM. Observed intrusions installed XMRig miners disguised as Microsoft Edge, a fake Edge update service, and PowerShell concealment scripts; five organizations were identified on the first reporting day. Versions through 10.3.4 were vulnerable.
- CVE-2026-105133 (CVSS 5.5) chains with command injection CVE-2026-105134 (CVSS 9.3).
- Unauthenticated attackers deploy JSP web shells and run commands as SYSTEM.
- Intrusions installed XMRig miners disguised as Edge and a fake update service.
- Exploitation began October 7; five organizations were identified the first day.
- AhsayCBS versions through 10.3.4 were still vulnerable at disclosure.
Vulnerabilities mentionedAll →
- CVE-2026-1051349.32%Unauthenticated OS Command Injection in AhsayCBSpublished · AhsayCBS PoC +1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-105134 |
Full article479 words · extracted from gbhackers.com · click to collapse
Threat actors are exploiting two zero-day vulnerabilities in Ahsay Cloud Backup Server (AhsayCBS) to compromise exposed backup servers without authentication and execute commands with SYSTEM privileges.
Observed intrusions have deployed web shells and cryptocurrency miners, exposing weaknesses in the infrastructure that centrally manages backup operations.
According to Field Effect’s October 9, 2026, report, exploitation began late October 7. Researchers disclosed the activity on October 8 and identified five affected organizations within the first day of reporting.
Two AhsayCBS Zero-Day Vulnerabilities
The attack chain combines CVE-2026-105133, an improper authentication vulnerability in the checkSysPwd function with a CVSS score of 5.5, and CVE-2026-105134, an operating system command injection vulnerability in the Replication Receiver component rated 9.3.
Together, the flaws enable remote attackers to gain privileged execution without credentials or user interaction. AhsayCBS manages backup operations, storage destinations, user accounts, policies, and replication services.
Its Replication Receiver accepts replicated backup data from other systems, while associated application programming interfaces let administrators configure receiver settings and manage trusted replication partners.
Researchers showed that chaining the vulnerabilities lets an unauthenticated attacker configure a malicious replication receiver, deploy a Java Server Pages web shell, and run commands as NT AUTHORITY\SYSTEM.
Successful exploitation requires network access to a vulnerable AhsayCBS interface, so externally accessible deployments are a priority to investigate. Observed attackers conducted reconnaissance and installed XMRig cryptocurrency miners disguised as Microsoft Edge processes.
They also created a fraudulent Edge update service for persistence and used PowerShell scripts intended to conceal mining activity from defenders. Web shells provided another way to execute commands on compromised hosts.
Although documented attacks focused on cryptomining, SYSTEM-level access creates broader risks. Depending on deployment permissions and integrations, attackers could access credentials, backup repositories, storage systems, and administrative functions.
Researchers did not report observing credential theft or backup manipulation in these intrusions. The potential impact increases when one deployment manages backups across multiple customers, locations, or business units.
Compromising that central administration point could threaten connected resources and undermine infrastructure needed for incident response and ransomware recovery.
Field Effect reported that versions through 10.3.4 remained vulnerable at disclosure. Administrators should inventory production, disaster recovery, test, and secondary deployments; verify versions; restrict management and replication access to trusted networks or VPNs; and install a vendor-fixed release when available.
Investigations should examine unexpected JSP files, suspicious child processes spawned by cbssvcX64.exe, unauthorized receiver configurations, PowerShell execution, and mining-related outbound connections.
Compromised hosts require checks for malicious services and persistence. Rebuild from known-good media and redeploy AhsayCBS to remove attacker modifications that application updates alone may leave behind.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.