Skip to content

AhsayCBS unauth RCE (CVE-2026-105134) exploited, no patch yet

Attackers chain two AhsayCBS flaws into unauthenticated SYSTEM RCE and drop XMRig miners. Huntress confirms active exploitation; every version through 10.3.4 is affected and no fix exists.

Published 3 min read

Two flaws in AhsayCBS, the centralized backup-server console used by MSPs and system integrators, are being chained for unauthenticated remote code execution as NT AUTHORITY\SYSTEM — and there is no patched version to run to. Huntress confirmed in-the-wild exploitation starting October 7, 2026, and as of October 8 had seen at least five organizations hit.

The CVEs, disclosed October 4: CVE-2026-105134 (critical) and CVE-2026-105133 (medium). Spain's INCIBE-CERT notes public exploit code exists for both.

What the bugs do

  • CVE-2026-105133 — improper authentication in the checkSysPwd function (com/ahsay/obs/api/ApiStructsAction.java). Used first, to bypass authentication.
  • CVE-2026-105134 — the critical one. The /rps/api/json/UpdateReceivers.do endpoint in the Replication Receiver component allows OS command injection, and its API accepts a random token in place of valid credentials. Used second, for code execution as SYSTEM.

Chained, an unauthenticated attacker reaches a root-equivalent shell on the backup server.

Affected versions — and the patch problem

There is no fixed release. Huntress is explicit, and corrected its own earlier reporting:

AhsayCBS versions up through 10.3.4 are affected by this issue.

Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities. [P]revious reporting indicated that 10.3.4 was not susceptible.

So "update to 10.3.4" — which circulated in early coverage — is wrong. Huntress says it has contacted Ahsay and, "until a patch is available," recommends restricting access to the management interface.

Exploitation status

Confirmed in the wild by Huntress, first seen 2026-10-07 23:20 UTC. Post-exploitation observed: JSP webshells in the CBS web app directory, then an XMRig cryptominer (edge.exe) masquerading as Microsoft Edge, a persistence service MicrosoftEdgeUpdateSvc running as SYSTEM via a modified NSSM utility (msedge.exe), a Task-Manager-aware PowerShell script (Taskgmr.ps1) that hides the miner, and the vulnerable WinRing0x64.sys driver loaded for kernel-level access.

Action checklist

  1. Assume no patch. Pull the AhsayCBS management interface off the public internet now — restrict to trusted IPs or require VPN. This is the only mitigation Huntress offers.
  2. Hunt for compromise against the IOCs below. If any match, Huntress says re-image the host from a trusted backup — attackers may have planted secondary backdoors.
  3. Look for cbssvcX64.exe spawning unexpected child processes, and a service named MicrosoftEdgeUpdateSvc.
  4. MSPs: your AhsayCBS box is a pivot into every client it backs up. Prioritize accordingly.

Indicators of compromise

Published by Huntress — reproduced verbatim:

IPs
177.4.12[.]11        (AS140227, Hong Kong)
38.60.252[.]110      (AS154177, Vietnam)
107.191.47[.]199     (AS20473, France)
185.220.236[.]49     (AS38136, Taiwan)
104.234.26[.]10      (AS134677, United States)
123.202.208[.]37     (AS9269, Hong Kong)

Mining pool
xmr.kryptex[.]network:8029   (51.195.127[.]124:8029)
user: krxYMRN97D/creativejs

Payload URLs (Alibaba Cloud OSS)
hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/Taskgmr.ps1
hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/edge.exe
hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/msedge.exe
hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/config.json
hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/WinRing0x64.sys

SHA256
msedge.exe (modified NSSM): 05f69ae6b2b89c1c4dcf836bff032232f11bf0109f2b498e2345045d06139034
edge.exe (XMRig miner):     4dcb0202fe8b2d4d7b183764e38184cd6ed50132786cc7e7d1f7f4bce1dd6f3d
Taskgmr.ps1:                481728a7c9c4c02be07051d9c1958d902ea6397ebb8952ab83944818e3d25d21

Huntress also published four Sigma rules in its threat-intel repository under 2026/2026-10/AhsayCBS_XMRig_Miner (unexpected AhsayCBS child process, fake Edge binary with daemonized flag, Task-Manager-aware service control, and WinRing0 driver download) — pull them from the source rather than hand-copying.

Context

Backup infrastructure keeps turning up as the soft target: own the system that holds every restore point and you own everything downstream. We covered the same logic in the Veeam Backup & Replication domain-user RCE earlier this year. The AhsayCBS twist is the missing patch — for now, network isolation is the whole defense.

Related stories