Skip to content

SecurityIndependently confirmed2 publishers2 min readPublished

Attackers chain two unpatched AhsayCBS flaws to plant webshells on MSP backup servers

Attackers are chaining two unpatched AhsayCBS flaws to run code as SYSTEM and plant webshells and XMRig miners, according to Huntress. Managed service providers are the main users of the console, so the hosts being hit are the ones that manage backup users and policies for clients.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Attackers chain two unpatched AhsayCBS flaws to plant webshells on MSP backup servers
Generated illustration

What happened

  • Two AhsayCBS flaws were identified on October 4: CVE-2026-105133, an authentication weakness in checkSysPwd, and CVE-2026-105134, a critical bug in the Replication Receiver API.
  • Huntress first saw the chain used against exposed systems at 23:20:15 UTC on October 7, 2026.
  • Attackers kept their foothold with a Windows service named MicrosoftEdgeUpdateSvc, built to pass for Edge's real updater and running a binary from Temp as SYSTEM.
  • Huntress said it has contacted Ahsay and shared the details of its research with the vendor.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure The bypass lets a random token stand in for valid credentials, so any AhsayCBS console with a reachable management interface is open to an attacker who holds no account.
  • contradiction Earlier reporting cleared version 10.3.4, and Huntress's October 8 update says it is vulnerable, so any server ruled safe by version number on that basis has to be checked again.
  • constraint A JSP webshell already written to the CBS application directory stays there after access is restricted or a patch lands, so locking down a console does not remove access an attacker already planted.

The severity ratings undersell the first bug. CVE-2026-105133 is rated medium [3]. In the intrusions Huntress observed, it is the step that gets the attacker past authentication, and CVE-2026-105134 then turns that access into code execution [5]. Huntress saw the chain in use about three days after the flaws were identified [18].

According to Huntress, intrusions went one of two ways after exploitation. In some, the attacker configured a malicious receiver and wrote a JSP webshell into the directory the CBS application serves [8]. In several others, cbssvcX64.exe ran commands that pulled Taskgmr.ps1, msedge.exe, edge.exe and config.json into the Temp folder from hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com [17].

The edge.exe file is XMRig, renamed to pass as a Microsoft Edge process. It connected on port 8029 to 51.195.127[.]124 and xmr.kryptex[.]network [9]. The msedge.exe file is a modified copy of the NSSM service utility, and Huntress believes the attackers used it to keep the miner running [12]. Huntress said Taskgmr.ps1 appears to be AI-assisted, judging by its commented code [16].

Huntress first spotted the activity in suspicious command lines spawning from cbssvcX64.exe [7]. Child processes under that binary are the first place to look.

The tooling is commodity. Huntress describes XMRig as a legitimate open-source Monero miner that attackers frequently install on compromised systems [10]. The same download host served the files across several incidents [17]. In my view the mining is opportunistic monetization of a bug that was days old [18]. For an MSP, the webshell matters more. It sits on the server that creates backup users and sets backup policies [2][8].

"Until a patch is available, we recommend restricting access to the management interface and investigating for signs of compromise," Huntress wrote [14].

What to watch

  • An Ahsay advisory or patch, and whether its affected-version list matches Huntress's finding on 10.3.4.
  • Reporting of attackers reaching backup data or moving from a CBS host into client networks, beyond mining and webshells.
  • New download hosts or mining pools beyond the single bucket and Kryptex pool Huntress listed, which would point to more than one operator.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence68
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence66
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Huntress is observing threat actors targeting vulnerabilities in AhsayCBS (Cloud Backup Server), the management console for Ahsay's backup software.

  2. [2]

    AhsayCBS is primarily used by managed service providers and system integrators; it centralizes control of backup operations, letting administrators create and manage users and configure backup policies.

  3. [3]

    On October 4, two vulnerabilities were identified in AhsayCBS, including CVE-2026-105133, a medium-severity flaw in the checkSysPwd function of ApiStructsAction.java that can lead to improper authentication.

Sources

2 independent publishers whose own reporting we read for this story.

  1. huntress.com

    1 article · October 8, 2026

    Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
  2. securityweek.com

    1 article · October 9, 2026

    Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories