Vulnerability
Published 2026-10-04
Verified 2026-10-09

AhsayCBS backup server CVE-2026-105134 (CVSS 10.0) and CVE-2026-105133 exploited in the wild: Huntress sees unauthenticated SYSTEM-level RCE, webshells and cryptominers at five organisations; 10.3.4 is also affected and no fix exists yet

AhsayCBS is the central management console for Ahsay's cloud backup software, used mainly by managed service providers (MSPs) and system integrators. Two flaws were published on 4 October 2026 (CNA VulDB, with public exploit code): CVE-2026-105133, an authentication bypass in the checkSysPwd function of the API (CVSS 3.1 7.3), and CVE-2026-105134, an OS command injection in the Replication Receiver endpoint /rps/api/json/UpdateReceivers.do (CVSS 3.1 10.0, CVSS 4.0 9.3), where a random token can stand in for valid credentials. The CVE records list versions up to 10.3.2 and point to 10.3.4 as the fix, but Huntress said on 8 October that 10.3.4 is also vulnerable and that it has told Ahsay. Huntress first saw exploitation at 23:20 UTC on 7 October and had seen five organisations targeted by 8 October: attackers chained the two bugs to run code as NT AUTHORITY\SYSTEM, set up a malicious replication receiver, dropped a JSP webshell into the CBS web directory, ran reconnaissance, installed XMRig cryptominers disguised as Microsoft Edge, kept them running with a renamed NSSM service posing as Edge Update, loaded the vulnerable WinRing0x64.sys driver, and added an apparently AI-written PowerShell script that closes Task Manager if it stays open overnight. Primary: Huntress; wire: SecurityWeek.

Product
Ahsay AhsayCBS (Cloud Backup Server) management console — API and Replication Receiver
Versions
CVE records: up to 10.3.2; Huntress: 10.3.4 also affected
CVSS
Exploited in Australia?
unknown
Patch to
No fixed version confirmed yet. Restrict the AhsayCBS web console and Replication Receiver to trusted IPs or VPN only, hunt for JSP files in the CBS web directory, unknown replication receivers, msedge.exe/NSSM services and WinRing0x64.sys, and apply Ahsay's fix as soon as it ships.

Primary: Huntress — Threat actors exploit critical AhsayCBS flaws to drop webshells and XMRig cryptominer (8 Oct 2026, updated 8 Oct 6pm ET) · Vendor: Ahsay — AhsayCBS v10.3.4 release notes (Huntress says 10.3.4 is still affected) · CVE: CVE-2026-105134, CVE-2026-105133 · SecurityWeek — Unpatched AhsayCBS vulnerabilities exploited in the wild (9 Oct 2026)

vulnerabilities cloud