"Post-exploitation, threat actors are conducting reconnaissance, dropping web shells, planting XMRig cryptominers masquerading as Microsoft Edge, and more," Huntress said.
The vulnerabilities: CVE-2026-105133 and CVE-2026-105134
Two recently disclosed flaws in the AhsayCBS backup utility have been identified as the entry point for active exploitation. CVE-2026-105133 (CVSS v4 score: 5.5) is described as an improper authentication vulnerability in the checkSysPwd() function within the "com/ahsay/obs/api/ApiStructsAction.java" component. CVE-2026-105134 (CVSS v4 score: 9.3) is an operating system command injection vulnerability in the Replication Receiver component. According to the published descriptions, an attacker able to chain these two defects can bypass authentication and execute arbitrary commands on affected systems.
Timeline and measured impact
CVE identifiers for the two flaws were not published until October 4, 2026. Huntress, the cybersecurity company tracking exploitation, reported that attempts to weaponize those flaws began on October 7, 2026, at 11:20 p.m. UTC. As of October 8, 2026, Huntress estimates that five organizations were targeted and affected by these exploits.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTechniques observed after compromise
Huntress’s post-exploitation findings show a distinct operational pattern. Attackers conducted reconnaissance, installed web shells and deployed XMRig cryptocurrency miners. The miners were found impersonating the Microsoft Edge browser by using the filename "edge.exe" to blend in with legitimate process names. A PowerShell script named "Taskgmr.ps1" was also dropped and launched via curl; Huntress flagged the script as likely AI-assisted and noted that it contains anti-analysis checks that suspend mining when the Windows Task Manager is opened.
Specifically, the Taskgmr.ps1 script is configured to terminate Task Manager at 6 p.m. if it had been left open for more than one hour overnight, behavior Huntress says is intended to frustrate live analysis and reduce detection. In at least one incident, operators used the built-in Windows binary "certutil.exe" to download a legitimate-but-vulnerable driver, "WinRing0x64.sys," into the TEMP folder — an action Huntress says was likely aimed at gaining kernel-level access to underlying hardware to optimize mining performance.
Patch status, advisories, and the zero-day claim
The National Vulnerability Database (NVD) advisories state that the issues are addressed in AhsayCBS version 10.3.4. However, Huntress subsequently revealed that that same version is impacted in practice, a divergence that the company says effectively turns the disclosures into zero-days. With that contradiction standing in the public record, Huntress recommended immediate operational controls where patching is not yet confirmed.
Absent a reliable patch, Huntress advised restricting access to the AhsayCBS management interface web service — specifically recommending that web access be limited to trusted IP addresses only or placed behind a VPN, since the exploit targets the externally accessible management web app.
What this means for technologists, affected enterprises, and IT administrators
- Technologists and security teams: Huntress’s findings point to an active RCE chain combined with evasive post-exploitation tooling. Teams should hunt for web shells, the "edge.exe" miner process, instances of Taskgmr.ps1, and evidence of certutil.exe downloading "WinRing0x64.sys" into TEMP as specific indicators of compromise mentioned in the report.
- Affected enterprises and procurement leaders: The divergence between NVD advisories and Huntress’s observations highlights a gap between published fixes and real-world remediation. Procurement and vendor-management leaders will need to press for verification that version 10.3.4 (or any replacement) fully mitigates both CVE-2026-105133 and CVE-2026-105134.
- IT administrators and day-to-day operators: Where patching cannot be confirmed, follow Huntress’s operational guidance: restrict external web access to the AhsayCBS management interface to trusted IPs or require VPN access, and scan endpoints for the specific artifacts Huntress identified (Taskgmr.ps1, edge.exe miners, web shells, and the downloaded WinRing0x64.sys driver).
The factual record for now is tightly bounded: two disclosed AhsayCBS flaws, public CVE identifiers issued October 4, active exploitation beginning October 7, and a small but real set of confirmed impacts by October 8. The immediate practical question the record leaves open is whether the vendor’s published fix in version 10.3.4 will be revalidated or superseded — and how quickly organizations running AhsayCBS can verify that their installations are not among the affected hosts Huntress identified. Until that verification is visible, Huntress’s operational mitigations remain the clearest path to reduce exposure.




