TL;DR
On October 7, security researchers detected active cyberattacks targeting the AhsayCBS backup platform. Threat actors chain two critical AhsayCBS vulnerabilities to achieve remote code execution on host servers. Administrators must immediately isolate exposed management consoles to prevent complete host compromise.
- Product: AhsayCBS
- Vulnerabilities: 2 flaws (CVE-2026-105134, CVE-2026-105133)
- Highest severity: 10.0 (Critical Β· CVSSv4)
- Worst impact: Replication Receiver UpdateReceivers.do os command injection
- Status: Exploited in the wild
- Action: Update to 10.3.4 now
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-105134 | 10 | Replication Receiver UpdateReceivers.do os command injection | 10.3.4 | Exploited in the wild |
| CVE-2026-105133 | 6.9 | API ApiStructsAction.java checkSysPwd improper authentication | 10.3.4 | Exploited in the wild |
Track every CVE that hits your stack the moment it's exploited.
Get free email alertsWhy It Matters
AhsayCBS acts as the central management console for backup software across thousands of organizations worldwide. Managed service providers rely heavily on this software to control backup operations and enforce storage policies. Consequently, these critical AhsayCBS vulnerabilities give adversaries a direct entry point into sensitive IT environments.
Huntress confirmed that threat actors are actively targeting organizations in the wild. As of October 8, investigators observed five organizations targeted in this campaign. Once inside, attackers deploy XMRig cryptominers and establish persistent administrative footholds. Furthermore, backup servers frequently hold vital administrative credentials and customer records. If an attacker controls the backup host, they can disrupt recovery operations completely. Therefore, securing this platform prevents widespread business disruptions across client networks.
How The Attack Works
The intrusion relies on chaining an authentication weakness with a remote code execution vulnerability. First, attackers target an authentication check in ApiStructsAction.java via CVE-2026-105133. According to Huntress, “The API contains an authentication bypass that could allow for a random token to substitute valid credentials.” This flaw lets unauthorized callers bypass primary authentication routines.
Next, the attackers exploit the Replication Receiver component through the UpdateReceivers.do endpoint via CVE-2026-105134. Researchers noted that “Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems.” Attackers configure a malicious receiver to upload a Java Server Page webshell into the web root.
Once the webshell lands, the backup service process executes system commands with NT AUTHORITY/SYSTEM privileges. The attackers then deploy malicious files into temporary directories. Specifically, they download Monero cryptominers disguised as Microsoft Edge binaries. They also install a modified NSSM utility to maintain system persistence across machine reboots.

Additionally, adversaries deploy an automated PowerShell script named Taskgmr.ps1 to hide malicious activity. This script monitors Windows Task Manager continuously. If an administrator opens Task Manager, the script terminates the miner service immediately. Once the administrator closes Task Manager, the script restarts the mining process. Attackers also install the vulnerable WinRing0x64.sys kernel driver to grant the miner direct hardware control.
Exploitation Status
Active exploitation in the wild is currently underway. Huntress confirmed that “Starting October 7 (23:20:15 UTC), Huntress began seeing threat actors exploiting the flaws to perform remote code execution on impacted hosts.” At present, attackers actively exploit these AhsayCBS vulnerabilities against exposed enterprise systems.
Affected Versions
All versions of AhsayCBS up through version 10.3.4 remain vulnerable to these exploits.
Patch And Mitigation Steps
The software vendor has not released an official patch yet. Therefore, system administrators must apply immediate defensive controls to minimize exposure.
First, restrict all public internet access to the AhsayCBS management web interface. Place the management console behind an enterprise firewall or virtual private network. Allow connections only from trusted, verified administrative IP addresses. Second, inspect server process trees for unusual child processes spawning from cbssvcX64.exe binaries.
If you discover indicators of compromise, re-image the host machine from a trusted backup. Attackers frequently plant secondary backdoors during active intrusions. Security analysts can also deploy Huntress Sigma rules to detect suspicious process execution chains.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!