AhsayCBS Zero-Days CVE-2026-105133/105134 Exploited to Mine Crypto on Backup Servers
🛡️ Security •

AhsayCBS Zero-Days CVE-2026-105133/105134 Exploited to Mine Crypto on Backup Servers

Attackers are chaining an auth bypass and command injection to run code as SYSTEM on internet-facing AhsayCBS backup servers, and the version listed as the fix is still vulnerable.

ahsaycbsbackup securityremote code executioncryptojackingbyovd

Threat actors are chaining two vulnerabilities in the AhsayCBS backup platform to take over internet-facing backup servers, and the version the vendor shipped as the fix does not close the hole. The result is unauthenticated remote code execution as SYSTEM on a machine that, by definition, holds copies of everything your organization backs up.

What Happened

On 4 October 2026 the National VulnerabilityVulnerability🛡️A weakness in software, hardware, or processes that can be exploited by attackers to gain unauthorized access or cause harm. Database published two flaws in AhsayCBS, Ahsay's centralized cloud backup server. CVE-2026-105133 is an authentication bypassAuthentication Bypass📖A security vulnerability that allows an attacker to circumvent the login verification process and gain unauthorized access to a system without providing valid credentials. in the `checkSysPwd` function inside `com/ahsay/obs/api/ApiStructsAction.java`. CVE-2026-105134 is an OS command injectionCommand Injection🛡️A security vulnerability that allows attackers to execute arbitrary operating system commands on the host system through a vulnerable application. in the Replication Receiver component, reached through the `/rps/api/json/UpdateReceivers.do` endpoint. Both are triggered by manipulating a parameter named `random`, and both are exploitable over the network without credentials.

VulDB scores the authentication bypass 5.5 under CVSS v4 and 7.3 under CVSS v3.1, and the command injection 9.3 under CVSS v4 and a maximum 10.0 under CVSS v3.1. Some early reporting flipped those severities, labeling the bypass critical and the injection medium. Treat the command injection as the critical one: it is the flaw that yields code execution.

Exploitation in the wild began on 7 October at 23:20:15 UTC, three days after disclosure. Huntress, the managed detection and response firm whose analysts Dray Agha, Olly Maxwell, Tyler Bohlmann and Amelia Casley published the breakdown on 8 October, counted five targeted organizations on the first day and a further incident shortly after. There is no sign yet of mass, indiscriminate scanning, but a public exploitExploit🛡️Code or technique that takes advantage of a vulnerability to cause unintended behavior, such as gaining unauthorized access. for the authentication bypass already exists.

The Patch That Is Not a Patch

The CVE records list AhsayCBS 10.3.4 as the fixed release. Huntress tested it and found 10.3.4 still vulnerable to both flaws. Ahsay's own 10.3.4 release notes, dated 5 August 2026, describe backup and connectivity bug fixes and name no security item matching these CVEs, and no version newer than 10.3.4 is published. In practice there is no effective patch, which is why several outlets are describing the pair as zero-days despite the CVE records claiming otherwise.

That gap matters for triage. An administrator who reads the NVD entry, confirms they are on 10.3.4, and moves on will believe they are safe while remaining fully exposed. A vendor-asserted fixed version only helps if someone verifies it actually resolves the flaw. This is a working example of why 'patched' from the vendor is not the same as 'not vulnerable', and why a severity or status field in an advisory is a starting point rather than a verdict.

Who Is Affected

AhsayCBS is the server-side console that drives Ahsay's backup suite: it manages backup policy, storage destinations, replication and user accounts. It is most commonly run by managed service providers and system integrators who back up many client environments from one platform. That deployment pattern is exactly what makes a compromise severe. A single exploited AhsayCBS host can expose stored backup data, the credentials it holds for connected client systems, and a path for lateral movementLateral Movement🛡️Techniques attackers use to move through a network after initial compromise, seeking additional systems to control and data to steal. into every environment it manages. Your backup server is a Tier-0 target, and this incident shows why that classification is not academic.

Every release through 10.3.4 is affected. Because there is no fixed build to move to, exposure is governed entirely by whether the management interface is reachable from untrusted networks.

Technical Analysis

The attack chains the two flaws cleanly. CVE-2026-105133 lets an attacker substitute an arbitrary token for valid credentials, satisfying the authentication check without a real login. With that bypass in hand, CVE-2026-105134 is used to configure a malicious replication receiver and drop a Java Server Page web shellWeb Shell🛡️A malicious script placed in a web server's content directory that lets an attacker execute commands through HTTP requests. Web shells are a common persistence mechanism after remote code execution and are detected by looking for unexpected files in webapp directories. into the application directory that AhsayCBS serves. Commands then run as NT AUTHORITY\SYSTEM.

Huntress observed the AhsayCBS service process, `cbssvcX64.exe` (and its 32-bit counterpart `cbssvcX86.exe`), spawning `curl` and `certutil` to pull a payload set from a cloud bucket at `imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com` into the `%TEMP%` directory. The staged files were `Taskgmr.ps1`, `msedge.exe`, `edge.exe`, `config.json` and `WinRing0x64.sys`. Despite the names, `edge.exe` is an XMRigXMRig🛡️An open-source, high-performance miner for the Monero cryptocurrency. It is widely abused by attackers who deploy it on compromised servers to mine coins using stolen compute, often disguised as a legitimate process. cryptocurrency miner and `msedge.exe` is a modified copy of the Non-Sucking Service Manager used to install it as a Windows service called `MicrosoftEdgeUpdateSvc`. The miner connected to the pool `xmr.kryptex[.]network:8029` and to `51.195.127[.]124:8029`.

Two touches stand out. `WinRing0x64.sys` is a legitimately signed but vulnerable kernel driver; loading it is a bring-your-own-vulnerable-driver move that gives the miner low-level hardware access to tune performance. And `Taskgmr.ps1`, which Huntress assesses was written with AI assistance, watches for Task Manager: it stops `MicrosoftEdgeUpdateSvc` when Task Manager opens so CPU usage looks normal, restarts it when Task Manager closes, and even terminates Task Manager outright at 18:00 or after it has been open for more than an hour during overnight windows. The goal is simple, to keep an administrator from spotting a pegged CPU.

The reported indicators include six source addresses (177.4.12[.]11, 38.60.252[.]110, 107.191.47[.]199, 185.220.236[.]49, 104.234.26[.]10 and 123.202.208[.]37) and file hashes for the three dropped binaries. Huntress published four Sigma rules covering unexpected child processes of the AhsayCBS service, the fake Edge binary running with a daemon flag, the Task Manager-aware service control, and the vulnerable driver download.

Immediate Actions

With no fixed build available, the response is containment, not patching.

  • Take the AhsayCBS management interface off the public internet. Restrict web access to trusted IP ranges only, or require a VPN to reach it. Learning how to restrict a web admin interface to trusted IP addresses is the single highest-value step here.
  • Hunt for compromise now. Look for unexpected children of `cbssvcX64.exe` or `cbssvcX86.exe`, a service named `MicrosoftEdgeUpdateSvc`, the staged filenames in `%TEMP%`, and outbound connections to the mining pool or the listed addresses. The techniques in How to Detect a Hidden Cryptominer on a Windows Server apply directly, including the process-lineage and service checks that defeat the Task Manager trick.
  • If you find indicators, assume full compromise. The host ran attacker code as SYSTEM, so re-image it from trusted media rather than trying to clean it, and investigate for secondary backdoors that outlast the miner. How BYOVD Attacks Use a Signed Driver to Reach the Windows Kernel explains why a loaded vulnerable driver can leave persistence a userland sweep will miss.
  • Rotate every credential the server stored or could reach, including the backup accounts for managed client systems.

Long-Term Outlook

Expect broader exploitation while the window stays open. A public exploit plus no real patch is the combination that turns a handful of targeted hits into opportunistic mass compromise, and cryptomining is often the least damaging thing an actor with SYSTEM on a backup server could choose to do next. Ransomware crews prize backup infrastructure precisely because disabling it removes the victim's recovery option.

The durable lessons are about where backup servers sit in your architecture and how you treat vendor fix claims. Why Your Backup Server Is a Tier-0 Target makes the case for giving these machines the same network isolation and monitoring you give a domain controller. And the 10.3.4 episode is a reminder to verify that an advisory's fixed version actually resolves the flaw before you close the ticket. Until Ahsay ships and someone confirms a build that holds, the only reliable control is keeping the console off any network an attacker can reach.

Sources

  • Huntress, "Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer" (8 Oct 2026): https://www.huntress.com/blog/ahsaycbs-flaws-exploit
  • BleepingComputer, "Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto" (9 Oct 2026): https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/
  • SecurityWeek, "Unpatched AhsayCBS Vulnerabilities Exploited in the Wild" (9 Oct 2026): https://www.securityweek.com/unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild/
  • The Hacker News, "Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge" (Oct 2026): https://thehackernews.com/2026/10/attackers-exploit-ahsaycbs-flaws-to.html
  • NVD / VulDB records for CVE-2026-105133 and CVE-2026-105134: https://nvd.nist.gov/vuln/detail/CVE-2026-105134
  • Ahsay AhsayCBS v10.3.4 release notes (5 Aug 2026): https://www.ahsay.com/en/support/help-centre/release-notes/cbs/v10.3.4