Skip to main content
Emerging ThreatsMalware & Ransomware

AhsayCBS flaws exploited to deploy webshells, crypto miners

Server room with rows of computer servers and storage equipment, one server showing signs of tampering.
On October 7, threat actors exploited two unpatched vulnerabilities in the AhsayCBS backup management platform — CVE-2026-105133 and CVE-2026-105134 — to breach and compromise at least five organizations.

How the attackers chained CVE-2026-105133 and CVE-2026-105134

Researchers at managed detection and response company Huntress observed the intrusions and reported that the adversary used a two-step attack chain. CVE-2026-105133, an authentication bypass with a public exploit, was used first to gain access to the AhsayCBS management interface. The attacker then leveraged CVE-2026-105134, an OS command injection vulnerability, to execute code on the host. This chaining of an auth bypass into command execution enabled the intruder to move from access to active compromise in the affected environments.

Payloads deployed: JSP webshells and a disguised XMRig miner

After gaining execution on affected hosts, Huntress observed reconnaissance activity followed by deployment of Java Server Page (JSP) webshells. The actor also downloaded a cryptocurrency miner — identified as XMRig — disguised on disk as edge.exe. The miner was configured to run persistently and to consume system resources for cryptocurrency mining.

Persistence and evasion: MicrosoftEdgeUpdateSvc, modified NSSM, and Taskgmr.ps1

The miner persisted via a service named “MicrosoftEdgeUpdateSvc,” which ran a file called msedge.exe. Huntress identified msedge.exe as a modified copy of the legitimate Non-Sucking Service Manager (NSSM) utility. In at least one incident the attacker also deployed the vulnerable WinRing0x64.sys driver, likely to attempt to unlock additional hardware resources for mining.

Huntress also recovered a PowerShell file named Taskgmr.ps1 that it describes as likely AI-assisted. That script concealed mining activity by stopping the miner service when Task Manager opened and restarting it when Task Manager closed. It additionally terminated Task Manager at 6 p.m. local time or if Task Manager remained open for more than an hour overnight, behavior intended to reduce the chance of discovery by operators.

Affected AhsayCBS versions and vendor response

The two flaws are reported as fixed in AhsayCBS 10.3.2, but Huntress found that Ahsay 10.3.4 — the then-current release — is also affected. “After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities,” Huntress wrote in an update cited by the reporting outlet. BleepingComputer contacted AhsayCBS to ask about its plans to fix the two flaws but had not received a response as of publication.

What this means for MSPs, system administrators, and defenders

  • Managed service providers (MSPs) and system administrators: AhsayCBS is commonly used by MSPs and system integrators; Huntress’s findings indicate administrators should assume exposure risk where the product is accessible. Huntress recommends restricting access to the AhsayCBS management interface to trusted IP addresses only and investigating signs of compromise in existing deployments.
  • Incident responders and defenders: If a compromise is confirmed, Huntress advises performing a full restore of the host from a safe backup because the attacker may have installed additional backdoors for prolonged persistence. Huntress also published indicators of compromise (IoCs) and four Sigma detection rules to help defenders identify related activity.

The observed campaign demonstrates a straightforward but effective combination: a public exploit for an authentication bypass followed by command injection to deliver persistent tooling. Huntress’s discovery that the vendor’s latest release remained vulnerable raises a pressing operational question for organizations that run AhsayCBS: whether a comprehensive patch or mitigation strategy will be released and how quickly administrators can restrict management access and hunt for indicators. BleepingComputer has sought comment from AhsayCBS and had not received one at the time of reporting.

Original reporting: BleepingComputer — Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto