Skip to content
Rush Commerce
Software & Dev3 min read

AhsayCBS flaws exploited, no patch yet: lock the console

Attackers chain AhsayCBS CVE-2026-105133 and CVE-2026-105134 for SYSTEM-level RCE on backup servers. Version 10.3.4 is still vulnerable. Restrict access now.

Attackers are chaining two AhsayCBS vulnerabilities to run code as SYSTEM on backup servers, and the version first named as the fix does not fix it. Huntress saw exploitation start on October 7 and later confirmed that AhsayCBS 10.3.4 is still vulnerable to CVE-2026-105134. If you — or your MSP — run Ahsay for backups, the management console needs to come off the open internet today.

What actually happened

AhsayCBS is the management console for Ahsay's backup software. Per Huntress, it is used mostly by managed service providers and system integrators to create users and set backup policy for their clients. Both CVEs were published on October 4:

  • CVE-2026-105133 (medium) — improper authentication in the system-password check.
  • CVE-2026-105134 (critical) — the Replication Receiver endpoint, /rps/api/json/UpdateReceivers.do, allows remote code execution as NT AUTHORITY\SYSTEM.

Chained, the first gets the attacker past authentication and the second gives them the box. Huntress first saw this at 23:20 UTC on October 7 and counted five targeted organizations by October 8.

What the attackers did next is a familiar playbook: JSP webshells dropped into the CBS web directory, a malicious replication receiver, and an XMRig Monero miner named edge.exe, running as a fake MicrosoftEdgeUpdateSvc service. A PowerShell script stops the miner when Task Manager opens. The kit also loads the vulnerable WinRing0 driver for kernel-level hardware access.

Early advisories said upgrading to 10.3.4 resolves the issue. Huntress's October 8 update says all versions through 10.3.4 are affected. Huntress has shared its research with Ahsay, and we found no confirmed fixed release as of this writing. Believe the people watching the attacks.

Why it matters for your business

A cryptominer is the noisy payload. The quiet fact is that someone had SYSTEM on the server that holds your backups — and the webshells stay after the miner gets killed. Backups are what you restore from after ransomware. An attacker who owns the backup console can delete them, poison them, or wait.

What to do, in order:

Take the console off the internet. Huntress's guidance: trusted IPs only, or VPN. With no patch, this is the fix.

Hunt before you trust it. Look for unexpected child processes of cbssvcX64.exe, JSP files you did not deploy, edge.exe in Temp, and a MicrosoftEdgeUpdateSvc service. Huntress published Sigma rules and IOCs.

If you find anything, rebuild. Huntress says attackers left secondary backdoors. Restore from a known-good backup — ideally one this server could not touch.

Ask your MSP the direct question. "Do you run AhsayCBS, and is the console reachable from the internet?" If they need a day to answer, that is your answer.

Key takeaways

  • Attackers chain CVE-2026-105133 (auth bypass) and CVE-2026-105134 (critical RCE) for SYSTEM access on AhsayCBS servers
  • Huntress saw exploitation from October 7 and five targeted organizations by October 8
  • AhsayCBS 10.3.4 is still vulnerable per Huntress — early "upgrade to 10.3.4" guidance is wrong
  • Payloads: JSP webshells, an XMRig miner disguised as Microsoft Edge, and the WinRing0 driver
  • Restrict the console to trusted IPs or VPN, hunt for the IOCs, and rebuild any host that shows them

A backup you can't trust is not a backup. We map which admin consoles a small business actually exposes, put backups where the production network can't delete them, and write the restore runbook before you need it. See what we operate, or send us your backup setup for a second look.

Sources: Huntress, Rapid7 vulnerability database.

  • #ahsaycbs
  • #cve
  • #backup
  • #msp
  • #patching
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.