Attackers are exploiting two unpatched flaws in AhsayCBS, a backup management console popular with IT providers, to run code remotely. Even the latest version, 10.3.4, is affected. If an MSP or integrator handles your backups, ask them today whether they use it and insist the console is not exposed to the internet.
Key facts
- CVE-2026-105133 (CVSS v4 5.5): improper authentication in the
checkSysPwd()function. - CVE-2026-105134 (CVSS v4 9.3): OS command injection in the Replication Receiver component.
- Attackers chain both: the first to bypass authentication, the second to execute code.
- The flaws were disclosed on 4 October. NIST warned that exploit code existed and that all versions up to 10.3.2 were affected. Huntress has confirmed 10.3.4 is affected too.
- According to Huntress, exploitation began on 7 October at 23:20 UTC, and as of 8 October an estimated five organisations had been hit (SecurityWeek).
Am I affected if I've never heard of AhsayCBS?
Possibly. AhsayCBS is a centralised console for managing cloud backups. Its typical users are managed service providers (MSPs) and integrators, not the end business. So if you outsource your backups, your provider may be running it without you knowing.
There is no published data on victims or on its use in Spain. But one question to your provider settles it.
The tricky part is the version. Both vulnerabilities were listed as fixed in 10.3.2. Anyone who upgraded thinking they were safe is not: Huntress confirms that 10.3.4, the latest, is still vulnerable (SecurityWeek).
What do attackers do once inside?
The attack targets the exposed web management service. Once in, the attacker performs reconnaissance, drops JSP webshells and downloads the XMRig cryptominer disguised as edge.exe (BleepingComputer).
In at least one incident they also downloaded the vulnerable WinRing0x64.sys driver, probably to gain kernel-level access (The Hacker News). That goes beyond mining: it is a bid for deep control of the machine.
Huntress has published indicators of compromise and four Sigma rules to detect this activity.
What to do today
- Ask your IT or backup provider whether they use AhsayCBS and which version. Get the answer in writing.
- Insist the management console is not reachable from the internet. VPN or trusted IPs only. This is what Huntress recommends while there is no patch.
- Ask for a check for signs of compromise: JSP webshells, the MicrosoftEdgeUpdateSvc service and the
edge.exeprocess, using Huntress's IoCs and Sigma rules. - If compromise is confirmed, restore the whole host from a clean backup. Removing what you find is not enough: the attacker may have left other backdoors.
- Check you have backups outside that platform and that restores have been tested.
- If you run AhsayCBS yourself, apply the access restrictions today. As of 9 October there was no patch.
What it means for a small business
This case carries an uncomfortable lesson: outsourcing your backups does not outsource the risk. Your provider's backup console has access to your most valuable data, and whoever controls it controls your safety net.
So far what has been seen is cryptomining. Our reading, which is inference and not a fact from the sources, is that an attacker in control of the backup console is one step away from something worse, such as ransomware. That is why step 5 is not optional: you need at least one backup that does not depend on that platform.
The other lesson is not to trust version numbers. "We're up to date" meant nothing here. What protects you is keeping the console off the internet, and you can demand that today without waiting for anyone.
If you're not sure what to ask your provider or how to verify the answer, we can help you review it through our cybersecurity service.
FAQ
Is there a patch for AhsayCBS?
As of 9 October, no. Version 10.3.4, the latest, is still vulnerable. The defence is to restrict access to the management console.
Is upgrading to the latest version enough?
No. The flaws were listed as fixed in 10.3.2, but Huntress has confirmed 10.3.4 is also affected.
What if we're confirmed as compromised?
Restore the whole host from a clean backup, because the attacker may have left other backdoors.