Two security flaws in AhsayCBS backup management software are currently being actively exploited by attackers to initiate remote access to the targeted systems, establish webshells, and cryptocurrency miners. Huntress reported that the flaws are being used in attacks that chain the two issues together to bypass authentication and run commands on vulnerable systems.
At least five companies have been reported targeted as of October 8, 2026.
The vulnerabilities tracked as CVE-2026-105133 and CVE-2026-105134 are generic for the AhsayCBS product, which serves as a centralized management system for managed service providers and system integrators that need to configure and control backup policies and schedules, storage, and users. Both flaws are caused by improper function arguments, which enable an attacker to bypass authentication and execute operating system commands.
The National Institute of Standards and Technology (NIST) published information about the disclosed security issues on October 4, 2026. Initially, all AhsayCBS versions up to 10.3.2. were considered to be affected. However, Huntress revealed that the company’s latest version at the time, 10.3.4., was also vulnerable.
One of the vulnerabilities, CVE-2026-105134, is a remote code execution issue that allows an unauthenticated attacker to run code with System-level privileges. It utilizes an API in AhsayCBS’s Replication Receiver component to establish a reverse connection to an attacker-controlled server.
An attacker can leverage the Replication Receiver bug by creating a fake replication receiver and delivering a Java Server Page webshell in the application directory served by AhsayCBS. After establishing initial access to the system, the threat actor performs inventory collection and uses Microsoft Edge-labeled XMRig cryptocurrency miners.
Huntress discovered that the attackers used an AI-powered PowerShell script that terminates itself if the Task Manager is opened for more than 50 seconds.
In addition, the script monitors whether the Task Manager has been closed and reopened.
The attackers also create a new Windows service that masquerades as Microsoft Edge Updater. It employs an alternate data stream and runs as a System process when using the Non-Sucking Service Manager tool. The service carries the msedge.exe file with custom modifications applied. The modifications to the Non-Sucking Service Manager allow it to maintain a durable process that restarts applications that were terminated due to an error or when the system restarts.
The attackers also installed a legitimate but deprecated kernel-mode driver called WinRing0x64.sys, which provides userspace programs with kernel-mode privileges. This component enables the cryptocurrency miner process to maintain persistence even after system reboots.
AhsayCBS software, utilized in the attacks, does not currently have a patch available.
As such, organizations are recommended to restrict access to the management portal by only allowing specific IP addresses or networks, such as those provided by a virtual private network.
In addition to that, administrators should monitor their systems for signs of compromise, such as webshells, unknown services, scripts, and cryptomining activities. Attackers are currently leveraging the AhsayCBS flaws to target businesses.
The widespread nature of the issues, as well as the utilization of the latest version of the software at the time of publication, should compel organizations using it to consider limiting access and conducting comprehensive reviews.
Read the original article:
