DKDKCISSPSearch
VulnerabilitiesDEVELOPING

Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners.

DKCISSP News DeskBleepingComputer9 Oct 2026, 10:47 pm
Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
Image courtesy of BleepingComputer. Original report
DKCISSP REPORT

Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners.

The two security issues exploited in attacks are tracked as CVE-2026-105133 , an authentication bypass vulnerability that has a public exploit, and CVE-2026-105134, which can be leveraged for OS command injection.

Both vulnerabilities are reported as fixed in AhsayCBS 10.3.2, but researchers at managed detection and response company (MDR) Huntress found that they also affect Ahsay 10.3.4, currently the latest version.

CVE-2026-105134 : A critical-severity vulnerability affecting /rps/api/json/UpdateReceivers.do of the component Replication Receiver in AhsayCBS, which can be exploited to achieve unauthenticated remote code execution as NT AUTHORITY/SYSTEM on the host.

After gaining access, Huntress observed the attacker perform reconnaissance, deploy Java Server Page (JSP) webshells, and download the XMRig miner disguised as edge.exe.

Until a patch is available, Huntress recommends that system administrators restrict access to the AhsayCBS management interface to trusted IP addresses only, and investigate signs of compromise.

The actors executed PowerShell to modify config.json in the Temp folder, before creating a Windows service ( MicrosoftEdgeUpdateSvc ) that is designed to look similar to the actual Microsoft Edge Update service ( edgeupdate ).

Starting 2026-10-07 23:20:15 UTC, Huntress observed threat actors exploiting the vulnerabilities to gain unauthenticated remote code execution and deploy webshells on exposed systems.

In the observed attacks, the threat actor chained the two vulnerabilities, CVE-2026-105133 first to bypass authentication and then CVE-2026-105134 for code execution.

Post-exploitation, threat actors are conducting reconnaissance, dropping webshells, planting XMRig cryptominers masquerading as Microsoft Edge, and more.

What happened

Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners.

The two security issues exploited in attacks are tracked as CVE-2026-105133 , an authentication bypass vulnerability that has a public exploit, and CVE-2026-105134, which can be leveraged for OS command injection.

What changed

Both vulnerabilities are reported as fixed in AhsayCBS 10.3.2, but researchers at managed detection and response company (MDR) Huntress found that they also affect Ahsay 10.3.4, currently the latest version.

CVE-2026-105134 : A critical-severity vulnerability affecting /rps/api/json/UpdateReceivers.do of the component Replication Receiver in AhsayCBS, which can be exploited to achieve unauthenticated remote code execution as NT AUTHORITY/SYSTEM on the host.

Who is affected

After gaining access, Huntress observed the attacker perform reconnaissance, deploy Java Server Page (JSP) webshells, and download the XMRig miner disguised as edge.exe.

Until a patch is available, Huntress recommends that system administrators restrict access to the AhsayCBS management interface to trusted IP addresses only, and investigate signs of compromise.

Why it matters

The actors executed PowerShell to modify config.json in the Temp folder, before creating a Windows service ( MicrosoftEdgeUpdateSvc ) that is designed to look similar to the actual Microsoft Edge Update service ( edgeupdate ).

Starting 2026-10-07 23:20:15 UTC, Huntress observed threat actors exploiting the vulnerabilities to gain unauthenticated remote code execution and deploy webshells on exposed systems.

Technical details

In the observed attacks, the threat actor chained the two vulnerabilities, CVE-2026-105133 first to bypass authentication and then CVE-2026-105134 for code execution.

Post-exploitation, threat actors are conducting reconnaissance, dropping webshells, planting XMRig cryptominers masquerading as Microsoft Edge, and more.

Organizations should restrict AhsayCBS management interface web access, as the exploit targets the externally accessible web app service on the host.

Response

They are post-exploitation detections written specifically for this campaign, and each targets a step the actor relies on to deploy, hide, or run the cryptominer, so alerting on any one of them gives defenders a chance to interrupt the chain.

Update 10/8/26 @ 6pm ET After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities.

What security teams should do

Huntress is currently working with potentially impacted organizations across our customer base to apply these mitigations; we recommend that all Ahsay customers adhere to these mitigations.

The miner persists on the host via a service named ‘MicrosoftEdgeUpdateSvc,’ which runs msedge.exe, identified by Huntress as a modified copy of the legitimate Non-Sucking Service Manager (NSSM) utility.

Attribution

BleepingComputer: Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners.

Huntress: On October 4, 2026, NVD disclosed two CVEs impacting the AhsayCBS backup utility: CVE-2026-105133 and CVE-2026-105134.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public DetailsThe Hacker News · 7 Oct 2026, 5:19 pmAtlassian warns of critical file-access flaw in Jira, ConfluenceBleepingComputer · 6 Oct 2026, 11:04 pmRed Hat’s Lightwell Project Remediates 400 Open-Source VulnerabilitiesInfosecurity Magazine · 6 Oct 2026, 6:31 pmDell System Update flaw allows attackers to gain root privileges (CVE-2026-86360) - Help Net SecurityHelp Net Security · 6 Oct 2026, 4:14 pm