AhsayCBS backup flaws exploited to plant miners, no patch confirmed
EditorialBy TrustList Editorial
Huntress saw the first attack at 23:20 UTC on 7 October, three days after the CVEs were published; the console is popular with managed service providers.
- Cybersecurity
- Backup Software
- MSP Software
- Vulnerability Management
About AhsayCBS backup flaws exploited to plant miners, no patch confirmed
AhsayCBS backup flaws exploited to plant miners, no patch confirmed
8 October 2026: Attackers are chaining two flaws in AhsayCBS, the central management console of Ahsay's backup software, to run commands as SYSTEM without logging in. Security firm Huntress has seen at least five organisations hit and could not confirm that a fix exists.
Not yet independently verified. No vendor advisory or fixed version has been seen. Huntress says it contacted Ahsay; check Ahsay's own site for a patch before relying on this. We will update this when it can be confirmed, and remove this note.
The CVEs are CVE-2026-105133, rated medium, and CVE-2026-105134, rated critical. The first lets an attacker bypass authentication by manipulating arguments to the checkSysPwd function. The second affects the /rps/api/json/UpdateReceivers.do endpoint of the Replication Receiver, where a random token is accepted in place of valid credentials, giving unauthenticated remote code execution as NT AUTHORITY\SYSTEM.
NVD published both on 4 October, and exploit code was released. Huntress first saw exploitation at 23:20 UTC on 7 October and published its warning the next day. Early NVD data suggested versions up to 10.3.2 were affected; Huntress corrected that on 8 October to say the range runs through 10.3.4, the latest it examined.
What the attackers did
Intruders dropped web shells and installed XMRig cryptocurrency miners named after Microsoft Edge files, with persistence through a service posing as Edge Update. One intrusion also loaded the vulnerable WinRing0x64.sys driver, which gives kernel-level access. Staged files came from an Alibaba Cloud storage bucket, and the miner reported to the Kryptex pool.
What Huntress advises
Until a patch is available, Huntress recommends limiting the AhsayCBS management interface to trusted IP addresses or placing it behind a VPN. Any host showing indicators of compromise should be re-imaged from a trusted backup, since attackers may leave secondary backdoors. Huntress published four Sigma rules covering unexpected child processes from the AhsayCBS service, fake Edge binaries, PowerShell service control and WinRing0 driver downloads.
Our backup software category lists 4 products.
AhsayCBS is widely used by managed service providers and integrators to run backup for many customers, so one compromised console can expose several client environments.
Company profile on TrustList: Ahsay Systems
Sources
- Huntress: AhsayCBS flaws exploited in the wild, 8 October 2026
- SecurityWeek: Unpatched AhsayCBS Vulnerabilities Exploited in the Wild, 9 October 2026
Categories & features
- Cybersecurity
- Backup Software
- MSP Software
- Vulnerability Management
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.