
AhsayCBS flaws exploited despite disputed fix in 10.3.4
AhsayCBS backup flaws are being used to install cryptocurrency miners, while Huntress says version 10.3.4 remains vulnerable despite published fix claims.
AhsayCBS backup software is being exploited to take over systems and install cryptocurrency miners, with conflicting information about whether its latest release fixes the underlying flaws. Huntress reports that version 10.3.4 remains vulnerable, despite National Vulnerability Database (NVD) advisories describing that version as the fix. For organisations using the software, upgrading to that release should therefore not be treated as evidence that the exposure is resolved.
The attacks combine two vulnerabilities to get past authentication, the check that establishes whether someone is allowed access, and then run commands on the affected machine. CVE-2026-105133 is an improper authentication flaw in the checkSysPwd() function within com/ahsay/obs/api/ApiStructsAction.java. It has a Common Vulnerability Scoring System (CVSS) version 4 severity score of 5.5. CVE-2026-105134 affects the Replication Receiver component and carries a score of 9.3. That second flaw permits operating system command injection, meaning an attacker can make the software pass unwanted instructions to the system beneath it.
The identifiers for both vulnerabilities were published on October 4, 2026. According to Huntress, exploitation began on October 7, 2026, at 11:20 p.m. UTC. By October 8, five targeted organisations were estimated to have been affected. In an update provided to The Hacker News, Huntress subsequently reported one additional incident using the same techniques, but said it had no evidence of broader exploitation. The attackers have not been identified, and these observations do not establish how many other installations might be exposed.
After gaining remote code execution, the ability to run their own instructions on another machine, the attackers performed reconnaissance to examine the compromised environment. Huntress also observed web shells, which are scripts that provide remote access through a web service, alongside XMRig cryptocurrency miners. Mining software uses a computer's processing resources to generate cryptocurrency. On a compromised backup host, that means resources intended for the organisation are being used for an unauthorised purpose.
The XMRig files used the name edge.exe to resemble the Microsoft Edge browser. The disguise is important for anyone reviewing the machine: a familiar-looking filename does not establish that a running program is genuine. Huntress also found a PowerShell script named Taskgmr.ps1. PowerShell is a Windows tool for running commands and automating tasks, while a script is a saved sequence of those instructions. The source describes the script as being launched through curl, a command-line tool commonly used to transfer data, to support the mining activity.
The script attempts to conceal the mining from someone inspecting the machine. It stops mining when Windows Task Manager, the application used to inspect running programs and resource use, is opened. The source also describes a rule that terminates Task Manager at 6 p.m. if it has been left open for more than an hour overnight. That timing description is not fully explained in the report, so the precise schedule is unclear. The observed behaviour nevertheless shows that an ordinary check of running programs may itself change what the malware does. Huntress suspects the script was written with assistance from an artificial intelligence (AI) tool, but that authorship has not been confirmed.
In at least one incident, the attackers used certutil.exe, a utility included with Windows, to download WinRing0x64.sys into the TEMP folder used for temporary files. WinRing0x64.sys is a legitimate but vulnerable driver, software that enables low-level interaction with hardware. The reported likely purpose was to obtain kernel-level access, meaning access within the operating system's privileged core, and improve mining performance. That purpose remains an assessment rather than a confirmed outcome of the download.
The unresolved patch status changes the immediate response. Although the NVD entries identify AhsayCBS 10.3.4 as addressing the issues, Huntress says that release is also affected. The report consequently describes the flaws as zero-days, vulnerabilities being exploited without an available fix. At the time of the reported activity, no effective patch was identified. Administrators should distinguish the database's fix claim from Huntress's finding rather than assume the version number alone establishes safety.
Huntress recommends restricting web access to the AhsayCBS management interface because the attack reaches the host through that externally accessible service. Access should be allowed only from trusted IP addresses, the network addresses of approved connections, or through a virtual private network (VPN), which provides a controlled private connection. Website owners who rely on a provider to manage backups should ask whether AhsayCBS is in use and who is responsible for limiting that access. Teams should also investigate signs of compromise, including the reported files and web shells: blocking new access does not establish that a previously exposed host is clean.
How to Protect Yourself
- Ask your backup provider or IT support whether your backups use AhsayCBS.
- Ask the person managing AhsayCBS to make its management page accessible only through approved connections or a private VPN connection.
- If you have been told that version 10.3.4 fixes the problem, ask your administrator to review Huntress's conflicting finding before considering the system safe.
- Ask IT support to check for Taskgmr.ps1, unexpected edge.exe files and other signs of intrusion rather than deleting files yourself.
- Report unexpected Task Manager closures to IT support if your organisation uses AhsayCBS.
Vulnerabilities & Fixes
- CVE-2026-105133 An improper authentication flaw in checkSysPwd(); Huntress recommends restricting management access because version 10.3.4 is reportedly still affected. View the fix & details →
- CVE-2026-105134 A command injection flaw in the Replication Receiver; restrict management access to trusted network addresses or a VPN while no effective patch is identified. View the fix & details →
Terms Explained
- authentication The process of checking whether a person or system is allowed to gain access.
- command injection A flaw that lets an attacker cause software to run unwanted system instructions.
- web shells Malicious scripts that let attackers control a compromised machine through a web service.
- cryptocurrency miners Programs that use a computer's processing power to generate digital currency.
- PowerShell A Windows tool used to run instructions and automate computer tasks.
- zero-days Vulnerabilities being exploited before an effective fix is available.
- virtual private network (VPN) A service that creates a protected connection to a private network.