Attackers exploit unpatched AhsayCBS flaws for webshells and miners
Attackers chained two AhsayCBS bugs for SYSTEM remote code execution, JSP webshells, and XMRig at about five organizations from 7 October 2026.
Huntress observed threat actors chaining CVE-2026-105133 and CVE-2026-105134 on exposed AhsayCBS consoles from 7 October 2026 to gain unauthenticated remote code execution as NT AUTHORITY\SYSTEM. The Hacker News and GBHackers rate CVE-2026-105133 at CVSS 5.5 as an authentication weakness in checkSysPwd and CVE-2026-105134 at CVSS 9.3 as command injection in the Replication Receiver; SecurityWeek says NIST disclosed both on 4 October 2026 with public exploit code, while GBHackers, citing Field Effect rather than Huntress, calls them zero-days and says the chain lets attackers configure a malicious receiver, deploy a JSP web shell, and run as SYSTEM. By 8 October, Huntress reported at least five organizations compromised—The Hacker News says about five, and GBHackers says five were identified on the first reporting day—with JSP webshells, XMRig miners named edge.exe and disguised as Microsoft Edge, a PowerShell script that stops mining when Task Manager stays open, persistence via a fake MicrosoftEdgeUpdateSvc service and a modified NSSM binary, and in one case the vulnerable WinRing0x64.sys driver, which The Hacker News says was fetched with certutil. Sources disagree on fixes: Ahsay told BleepingComputer both issues were fixed in 10.3.2 and NVD says 10.3.4 fixes them, while Huntress, SecurityWeek, and BleepingComputer report that 10.3.4, described as the latest version, remains vulnerable; GBHackers says versions through 10.3.4 were vulnerable. Advisories recommend restricting the management interface to trusted addresses or a VPN until a patch is available. BleepingComputer notes AhsayCBS is backup software common among MSPs.
- CVE-2026-105133 (CVSS 5.5, authentication weakness in checkSysPwd) is chained with CVE-2026-105134 (CVSS 9.3, OS command injection in the Replication Receiver UpdateReceivers.do API) for unauthenticated RCE as NT AUTHORITY\SYSTEM.
- Huntress says exploitation of exposed AhsayCBS consoles began 7 October 2026; SecurityWeek says NIST disclosed the flaws on 4 October 2026 with public exploit code, while GBHackers, citing Field Effect, calls them zero-days.
- By 8 October Huntress reported at least five organizations compromised; The Hacker News says about five, and GBHackers says five were identified on the first reporting day.
- Intruders deployed JSP webshells and XMRig miners named edge.exe and disguised as Microsoft Edge, plus a PowerShell script that stops mining when Task Manager stays open.
- Persistence used a fake MicrosoftEdgeUpdateSvc service and a modified NSSM binary; one case loaded vulnerable WinRing0x64.sys, which The Hacker News says was fetched with certutil.
- Patch status is disputed: Ahsay told BleepingComputer both issues were fixed in 10.3.2 and NVD says 10.3.4 fixes them, but Huntress, SecurityWeek, and BleepingComputer say 10.3.4, called the latest, remains vulnerable.
- Advisories recommend restricting the management interface to trusted addresses or a VPN until a patch exists; BleepingComputer notes AhsayCBS is backup software common among MSPs.
Coverage timelineoldest first · each row is one article
- · 2d agoThreat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
Huntress· 82
Huntress saw attackers chain two AhsayCBS flaws for SYSTEM RCE, webshells, and XMRig mining.
- · 1d agoUnpatched AhsayCBS Vulnerabilities Exploited in the Wild
SecurityWeek· 78
Huntress says attackers are exploiting unpatched AhsayCBS flaws for unauthenticated RCE, webshells, and cryptominers.
- · 1d ago
Vulnerabilities in this storyAll →
- CVE-2026-1051349.32%Unauthenticated OS Command Injection in AhsayCBSpublished · AhsayCBS PoC +1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-105134 |