Vulnerabilities
AhsayCBS backup servers hit by unpatched RCE chain
Two AhsayCBS flaws are chained for SYSTEM-level code execution, and 10.3.4 is still vulnerable. Who is exposed, how it works, and what to check.
Attackers are chaining two flaws in AhsayCBS, the server component of the Ahsay backup platform that receives and stores client backups. CVE-2026-105133 lets a request skip authentication, and CVE-2026-105134 lets that request run operating system commands, which on Windows execute as SYSTEM. Huntress saw the first exploitation on October 7 at 23:20 UTC and had found five targeted organisations among its customers by October 8. The attackers dropped web shells and ran XMRig cryptocurrency miners named to look like Microsoft Edge.
Sources disagree on whether a fix exists. The National Vulnerability Database (NVD) entries, published October 4, say versions up to 10.3.2 are affected and that upgrading to 10.3.4 resolves both issues. On the evening of October 8, Huntress updated its report: after further testing, 10.3.4 is affected too. SecurityWeek and The Hacker News both carried that correction on October 9, and neither found a statement from Ahsay. As of this writing there is no confirmed fixed release, so treat every AhsayCBS server, 10.3.4 included, as exploitable.
How it works
AhsayCBS exposes a web management interface and a set of JSON APIs on the same service. One of those APIs belongs to the Replication Receiver, the component that accepts replicated backup data from another AhsayCBS server. Its configuration endpoint is /rps/api/json/UpdateReceivers.do.
CVE-2026-105133 sits in the checkSysPwd function of com/ahsay/obs/api/ApiStructsAction.java, which, as its name suggests, checks the system password before an API call goes ahead. According to the NVD entry, manipulating a request argument called random makes that check pass. Huntress describes it as an authentication bypass where a random token substitutes for valid credentials. The NVD scores it CVSS 4.0 at 5.5 (medium) and CVSS 3.1 at 7.3.
CVE-2026-105134 is an OS command injection in the same UpdateReceivers.do endpoint, through the same random argument: the value reaches a system command without being sanitised, so shell syntax in it runs on the host. Combined with CVE-2026-105133 the attacker needs no credentials at all, which is why the NVD gives it CVSS 4.0 9.3 and CVSS 3.1 10.0. Both entries were filed by VulDB as the CVE Numbering Authority and say a public exploit was already available at disclosure.
What attackers are doing
Exploitation started three days after the CVEs went public. Huntress saw commands spawned directly by cbssvcX64.exe, the main AhsayCBS Windows service. In one intrusion the attacker configured a malicious replication receiver and placed a JavaServer Pages (JSP) web shell, a script that runs commands sent over HTTP, in the application directory the CBS web server serves. Others went straight to downloading tools with curl and certutil.exe.
The payload was a miner. XMRig was saved as edge.exe, and a modified copy of NSSM, a utility that runs any program as a Windows service, was saved as msedge.exe. A new Windows service named to resemble the Microsoft Edge Update service runs it with SYSTEM rights and restarts the miner after crashes and reboots. A PowerShell script, Taskgmr.ps1, which Huntress believes was written with AI help, stops the service whenever Task Manager is open and kills Task Manager at 18:00 or after it has been open over an hour overnight, which hides the miner's CPU use from anyone who opens Task Manager to look. In at least one case certutil.exe pulled WinRing0x64.sys, a legitimate but vulnerable kernel driver, into the Temp folder to give the miner low-level hardware access.
Mining is the visible goal so far. An attacker with SYSTEM on a backup server can also read, alter or delete the backups it holds, so a quiet miner today is no assurance about what the next operator will do. CVE-2026-105134 was not in the CISA Known Exploited Vulnerabilities catalog as of its October 8 release.
What to do
1. Take the interface off the internet
With no confirmed fix, access control is the only mitigation available. Huntress recommends allowing the AhsayCBS management interface only from trusted IP addresses, or only over a VPN. Apply this at the firewall in front of the server, and remember that any client backup or replication traffic you still allow in reaches the same service, so limit those sources to known addresses as well. If a web application firewall (WAF) sits in front, block requests to /rps/api/json/UpdateReceivers.do from anywhere that is not a replication partner.
Upgrading to 10.3.4 does no harm, but do not mark the server as fixed because of it. Watch Ahsay's release notes for a build that names both CVEs.
2. Check whether you were hit
- In EDR or Sysmon process creation logs (event ID 1), look for any child process of
cbssvcX64.exeorcbssvcX86.exe. Huntress notes that web shell commands show up as direct children of the service, andcmd.exe,powershell.exe,curl.exeorcertutil.exeunder it is a strong sign. - Search user Temp folders for
edge.exe,msedge.exe,config.json,Taskgmr.ps1andWinRing0x64.sys. A real Edge never runs from Temp. - Run
Get-CimInstance Win32_Service | Where-Object PathName -like '*\Temp\*'to list services whose binary lives in a Temp folder, and compare any Edge-named service against a clean machine. - In the AhsayCBS console, review the Replication Receiver list for entries nobody created, and look for new
.jspfiles in the web application directory since October 4. - On the firewall, check outbound connections from the server to mining pools and to cloud storage hosts it has no reason to contact. Huntress published the IP addresses, staging domain, pool address and file hashes, plus four Sigma detection rules.
Ahsay's own guidance tells customers to exclude cbssvcX64.exe and the AhsayCBS install folder from antivirus scanning, and since version 7.17 the installer adds the process to the Windows Defender exclusion list itself. That makes behavioural and network signals more reliable here than file scanning: a dropped JSP shell in an excluded folder may never be scanned.
3. If you find indicators
Huntress advises re-imaging the host from a trusted backup rather than cleaning it, because it saw attackers leave secondary backdoors. Rebuild, restrict the interface before it goes back online, then rotate the AhsayCBS administrator passwords, any replication credentials, and any service account the server used. Check the integrity of stored backup sets before relying on them for a restore.
Where backup servers fit
Backup platforms often sit outside the normal patch cycle and reachable from the internet so remote clients can send data. They also hold copies of everything worth stealing. Put them in the same exposure review and EDR coverage as your mail and VPN gateways, and make sure an antivirus exclusion for performance is matched by process monitoring on the excluded binary.
Our attack surface management work finds backup consoles and other admin interfaces exposed to the internet, and security operations can hunt for the process and service patterns above across your estate. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: Huntress, SecurityWeek, The Hacker News, NVD CVE-2026-105133, NVD CVE-2026-105134, OpenCVE, Ahsay antivirus exclusion guide, CISA KEV catalog.