Skip to content
Quantum Secure Labs
Cybersecurity News

Attackers exploit two unpatched AhsayCBS flaws, and the latest version, 10.3.4, is still vulnerable

Attackers are exploiting two unpatched flaws in AhsayCBS, a backup management console popular with IT providers, to run code remotely. Even the latest version, 10.3.4, is affected. If an MSP or integrator handles your…

By Quantum Secure Labs4 min read
Servidores en un centro de datos que almacenan copias de seguridad
In this article

Attackers are exploiting two unpatched flaws in AhsayCBS, a backup management console popular with IT providers, to run code remotely. Even the latest version, 10.3.4, is affected. If an MSP or integrator handles your backups, ask them today whether they use it and insist the console is not exposed to the internet.

Key facts

  • CVE-2026-105133 (CVSS v4 5.5): improper authentication in the checkSysPwd() function.
  • CVE-2026-105134 (CVSS v4 9.3): OS command injection in the Replication Receiver component.
  • Attackers chain both: the first to bypass authentication, the second to execute code.
  • The flaws were disclosed on 4 October. NIST warned that exploit code existed and that all versions up to 10.3.2 were affected. Huntress has confirmed 10.3.4 is affected too.
  • According to Huntress, exploitation began on 7 October at 23:20 UTC, and as of 8 October an estimated five organisations had been hit (SecurityWeek).

Am I affected if I've never heard of AhsayCBS?

Possibly. AhsayCBS is a centralised console for managing cloud backups. Its typical users are managed service providers (MSPs) and integrators, not the end business. So if you outsource your backups, your provider may be running it without you knowing.

There is no published data on victims or on its use in Spain. But one question to your provider settles it.

The tricky part is the version. Both vulnerabilities were listed as fixed in 10.3.2. Anyone who upgraded thinking they were safe is not: Huntress confirms that 10.3.4, the latest, is still vulnerable (SecurityWeek).

What do attackers do once inside?

The attack targets the exposed web management service. Once in, the attacker performs reconnaissance, drops JSP webshells and downloads the XMRig cryptominer disguised as edge.exe (BleepingComputer).

In at least one incident they also downloaded the vulnerable WinRing0x64.sys driver, probably to gain kernel-level access (The Hacker News). That goes beyond mining: it is a bid for deep control of the machine.

Huntress has published indicators of compromise and four Sigma rules to detect this activity.

What to do today

  1. Ask your IT or backup provider whether they use AhsayCBS and which version. Get the answer in writing.
  2. Insist the management console is not reachable from the internet. VPN or trusted IPs only. This is what Huntress recommends while there is no patch.
  3. Ask for a check for signs of compromise: JSP webshells, the MicrosoftEdgeUpdateSvc service and the edge.exe process, using Huntress's IoCs and Sigma rules.
  4. If compromise is confirmed, restore the whole host from a clean backup. Removing what you find is not enough: the attacker may have left other backdoors.
  5. Check you have backups outside that platform and that restores have been tested.
  6. If you run AhsayCBS yourself, apply the access restrictions today. As of 9 October there was no patch.

What it means for a small business

This case carries an uncomfortable lesson: outsourcing your backups does not outsource the risk. Your provider's backup console has access to your most valuable data, and whoever controls it controls your safety net.

So far what has been seen is cryptomining. Our reading, which is inference and not a fact from the sources, is that an attacker in control of the backup console is one step away from something worse, such as ransomware. That is why step 5 is not optional: you need at least one backup that does not depend on that platform.

The other lesson is not to trust version numbers. "We're up to date" meant nothing here. What protects you is keeping the console off the internet, and you can demand that today without waiting for anyone.

If you're not sure what to ask your provider or how to verify the answer, we can help you review it through our cybersecurity service.

FAQ

Is there a patch for AhsayCBS?

As of 9 October, no. Version 10.3.4, the latest, is still vulnerable. The defence is to restrict access to the management console.

Is upgrading to the latest version enough?

No. The flaws were listed as fixed in 10.3.2, but Huntress has confirmed 10.3.4 is also affected.

What if we're confirmed as compromised?

Restore the whole host from a clean backup, because the attacker may have left other backdoors.

Sources

Worried about a threat like this one?

We review your exposure and show you how to protect yourself.

See our cybersecurity service

Cybersecurity News

FortiBleed is still active: FBI warns of attacks on FortiGate firewalls using stolen credentials

The FBI and the US Secret Service warn that FortiBleed is still active: attackers are getting into Fortinet FortiGate firewalls and SSL VPNs with stolen or reused credentials, sometimes locking administrators out. If…

Cybersecurity News

Attackers are exploiting critical CVE-2026-21589 in Jira and Confluence Data Center

Since 7 October, attackers have been trying to exploit CVE-2026-21589, a critical flaw that lets anyone read files without authentication in eight self-hosted Atlassian Data Center products, including Jira, Confluence…

Cybersecurity News

A malicious spreadsheet can run code in LibreOffice and OpenOffice; only LibreOffice has a patch

A malicious spreadsheet can run an attacker's code in LibreOffice and Apache OpenOffice as soon as it is opened, with no macro warning, if Java is enabled. It affects any company using these suites. Update LibreOffice…

Want to apply these ideas to your business?

Tell us about your case and we'll show you how to apply these strategies to your project.