SecurityIndependently confirmed2 publishers2 min readPublished
Attackers chain two unpatched AhsayCBS flaws to plant webshells on MSP backup servers
Attackers are chaining two unpatched AhsayCBS flaws to run code as SYSTEM and plant webshells and XMRig miners, according to Huntress. Managed service providers are the main users of the console, so the hosts being hit are the ones that manage backup users and policies for clients.
The Watch · Security desk

What happened
- Two AhsayCBS flaws were identified on October 4: CVE-2026-105133, an authentication weakness in checkSysPwd, and CVE-2026-105134, a critical bug in the Replication Receiver API.
- Huntress first saw the chain used against exposed systems at 23:20:15 UTC on October 7, 2026.
- Attackers kept their foothold with a Windows service named MicrosoftEdgeUpdateSvc, built to pass for Edge's real updater and running a binary from Temp as SYSTEM.
- Huntress said it has contacted Ahsay and shared the details of its research with the vendor.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure The bypass lets a random token stand in for valid credentials, so any AhsayCBS console with a reachable management interface is open to an attacker who holds no account.
- contradiction Earlier reporting cleared version 10.3.4, and Huntress's October 8 update says it is vulnerable, so any server ruled safe by version number on that basis has to be checked again.
- constraint A JSP webshell already written to the CBS application directory stays there after access is restricted or a patch lands, so locking down a console does not remove access an attacker already planted.
The severity ratings undersell the first bug. CVE-2026-105133 is rated medium [3]. In the intrusions Huntress observed, it is the step that gets the attacker past authentication, and CVE-2026-105134 then turns that access into code execution [5]. Huntress saw the chain in use about three days after the flaws were identified [18].
According to Huntress, intrusions went one of two ways after exploitation. In some, the attacker configured a malicious receiver and wrote a JSP webshell into the directory the CBS application serves [8]. In several others, cbssvcX64.exe ran commands that pulled Taskgmr.ps1, msedge.exe, edge.exe and config.json into the Temp folder from hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com [17].
The edge.exe file is XMRig, renamed to pass as a Microsoft Edge process. It connected on port 8029 to 51.195.127[.]124 and xmr.kryptex[.]network [9]. The msedge.exe file is a modified copy of the NSSM service utility, and Huntress believes the attackers used it to keep the miner running [12]. Huntress said Taskgmr.ps1 appears to be AI-assisted, judging by its commented code [16].
Huntress first spotted the activity in suspicious command lines spawning from cbssvcX64.exe [7]. Child processes under that binary are the first place to look.
The tooling is commodity. Huntress describes XMRig as a legitimate open-source Monero miner that attackers frequently install on compromised systems [10]. The same download host served the files across several incidents [17]. In my view the mining is opportunistic monetization of a bug that was days old [18]. For an MSP, the webshell matters more. It sits on the server that creates backup users and sets backup policies [2][8].
"Until a patch is available, we recommend restricting access to the management interface and investigating for signs of compromise," Huntress wrote [14].
What to watch
- An Ahsay advisory or patch, and whether its affected-version list matches Huntress's finding on 10.3.4.
- Reporting of attackers reaching backup data or moving from a CBS host into client networks, beyond mining and webshells.
- New download hosts or mining pools beyond the single bucket and Kryptex pool Huntress listed, which would point to more than one operator.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence66
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Huntress is observing threat actors targeting vulnerabilities in AhsayCBS (Cloud Backup Server), the management console for Ahsay's backup software.
- [2]
AhsayCBS is primarily used by managed service providers and system integrators; it centralizes control of backup operations, letting administrators create and manage users and configure backup policies.
- [3]
On October 4, two vulnerabilities were identified in AhsayCBS, including CVE-2026-105133, a medium-severity flaw in the checkSysPwd function of ApiStructsAction.java that can lead to improper authentication.
- [4]
CVE-2026-105134 is a critical-severity vulnerability in /rps/api/json/UpdateReceivers.do of the Replication Receiver component that can be exploited for unauthenticated remote code execution as NT AUTHORITY/SYSTEM; the API contains an authentication bypass that could allow a random token to substitute for valid credentials.
- [5]
Huntress is seeing the two vulnerabilities chained: CVE-2026-105133 to bypass authentication, then CVE-2026-105134 to gain code execution.
- [6]
Starting 2026-10-07 23:20:15 UTC, Huntress observed threat actors exploiting the vulnerabilities to gain unauthenticated remote code execution and deploy webshells on exposed systems.
- [7]
Huntress initially picked up on several suspicious command lines spawning from the AhsayCBS executable cbssvcX64.exe.
- [8]
After exploitation, a threat actor configured a malicious receiver and dropped a JSP webshell into the application directory served by the CBS application; in some incidents webshells were deployed immediately after exploitation.
- [9]
On several endpoints the XMRig miner, renamed edge.exe to masquerade as a Microsoft Edge process, was dropped in Temp folders and established connections on port 8029 to an XMR pool (51.195.127[.]124:8029, xmr.kryptex[.]network).
- [10]
Huntress describes XMRig as a legitimate open-source Monero miner that attackers frequently install on compromised systems to covertly consume CPU resources and generate cryptocurrency.
- [11]
The actors used PowerShell to modify config.json and created a Windows service, MicrosoftEdgeUpdateSvc, designed to look like the real Microsoft Edge Update service (edgeupdate), configured to run msedge.exe from the Temp folder with SYSTEM privileges for persistence.
- [12]
msedge.exe is a modified copy of the legitimate NSSM utility, which the threat actors likely used to maintain persistence for edge.exe.
- [13]
Huntress has contacted Ahsay and shared the details of its research.
- [14]
"Until a patch is available, we recommend restricting access to the management interface and investigating for signs of compromise."
ReportedSupportedSource: Huntress writeup2 sources— create a free account to open themView cited source - [15]
In an October 8, 2026 6pm ET update, Huntress determined that Ahsay 10.3.4 is also affected by these vulnerabilities; previous reporting indicated 10.3.4 was not susceptible.
- [16]
Taskgmr.ps1 appears to be an AI-assisted script, given the commented code.
- [17]
Across several other incidents, cbssvcX64.exe spawned commands that dropped Taskgmr.ps1, msedge.exe, edge.exe and config.json into %TEMP% or AppData/Local/Temp from hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com.
- [18]
Huntress's first observed exploitation came about three days after the two flaws were identified.
Sources
2 independent publishers whose own reporting we read for this story.
- huntress.comThreat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
1 article · October 8, 2026
- securityweek.comUnpatched AhsayCBS Vulnerabilities Exploited in the Wild
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Managed service provider securityFollow
- Actively Exploited Vulnerabilities and KEV MandatesFollow
- CryptojackingFollow
- Backup Software SecurityFollow