Skip to content
TrustList
News

AhsayCBS backup flaws exploited to plant miners, no patch confirmed

Editorial

By TrustList Editorial

Huntress saw the first attack at 23:20 UTC on 7 October, three days after the CVEs were published; the console is popular with managed service providers.

About AhsayCBS backup flaws exploited to plant miners, no patch confirmed

AhsayCBS backup flaws exploited to plant miners, no patch confirmed

8 October 2026: Attackers are chaining two flaws in AhsayCBS, the central management console of Ahsay's backup software, to run commands as SYSTEM without logging in. Security firm Huntress has seen at least five organisations hit and could not confirm that a fix exists.

Not yet independently verified. No vendor advisory or fixed version has been seen. Huntress says it contacted Ahsay; check Ahsay's own site for a patch before relying on this. We will update this when it can be confirmed, and remove this note.

The CVEs are CVE-2026-105133, rated medium, and CVE-2026-105134, rated critical. The first lets an attacker bypass authentication by manipulating arguments to the checkSysPwd function. The second affects the /rps/api/json/UpdateReceivers.do endpoint of the Replication Receiver, where a random token is accepted in place of valid credentials, giving unauthenticated remote code execution as NT AUTHORITY\SYSTEM.

NVD published both on 4 October, and exploit code was released. Huntress first saw exploitation at 23:20 UTC on 7 October and published its warning the next day. Early NVD data suggested versions up to 10.3.2 were affected; Huntress corrected that on 8 October to say the range runs through 10.3.4, the latest it examined.

What the attackers did

Intruders dropped web shells and installed XMRig cryptocurrency miners named after Microsoft Edge files, with persistence through a service posing as Edge Update. One intrusion also loaded the vulnerable WinRing0x64.sys driver, which gives kernel-level access. Staged files came from an Alibaba Cloud storage bucket, and the miner reported to the Kryptex pool.

What Huntress advises

Until a patch is available, Huntress recommends limiting the AhsayCBS management interface to trusted IP addresses or placing it behind a VPN. Any host showing indicators of compromise should be re-imaged from a trusted backup, since attackers may leave secondary backdoors. Huntress published four Sigma rules covering unexpected child processes from the AhsayCBS service, fake Edge binaries, PowerShell service control and WinRing0 driver downloads.

Our backup software category lists 4 products.

AhsayCBS is widely used by managed service providers and integrators to run backup for many customers, so one compromised console can expose several client environments.

Company profile on TrustList: Ahsay Systems

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy