Critical security flaws in AhsayCBS exploited for webshells and crypto miners
What happened
Threat Intelligence , Vulnerability Management Critical vulnerabilities in AhsayCBS exploited for webshells and crypto miners October 11, 2026 Share By SC Staff (Adobe Stock) Threat actors are actively exploiting two vulnerabilities, one critical and one medium-severity, in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. Although reported as fixed in AhsayCBS 10.3.2, researchers found they also affect the latest version, 10.3.4.
Threat actors are actively exploiting two vulnerabilities, one critical and one medium-severity, in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. These vulnerabilities, still unpatched in some versions, are being used to gain unauthorized access to systems typically managed by managed service providers and system integrators, with further coverage provided by Bleeping Computer.
The attacks chain two vulnerabilities: CVE-2026-105133 (the public catalogue number for a specific software flaw), an authentication bypass with a public exploit, and CVE-2026-105134, which allows for OS command injection. After bypassing authentication, attackers deploy Java Server Page (JSP) webshells and the XMRig cryptocurrency miner, disguised as edge.exe.
Key facts
- Although reported as fixed in AhsayCBS 10.3.2, researchers — found: they also affect the latest version, 10.3.4
Sources & evidence
- SC Media Reporting source
Critical vulnerabilities in AhsayCBS exploited for webshells and crypto miners ↗
https://www.scworld.com/brief/critical-vulnerabilities-in-ahsaycbs-exploited-for-webshells-and-crypto-miners