Critical AhsayCBS Vulnerabilities Exploited in the Wild: Immediate Actions Needed

www.news4hackers.com-critical-ahsaycbs-vulnerabilities-exploited-in-the-wild-immediate-actions-needed-critical-ahsaycbs-vulnerabilities-exploited-in-the-wild-immediate-actions-needed

Unpatched AhsayCBS vulnerabilities are being exploited in real-world attacks, allowing remote code execution and deployment of malicious payloads.

Overview of the Vulnerabilities

Vulnerabilities Disclosed

Hackers have been leveraging two unpatched security flaws in the AhsayCBS backup system to achieve remote code execution (RCE), according to cybersecurity firm Huntress. The vulnerabilities, designated as CVE-2026-105133 and CVE-2026-105134, enable attackers to manipulate function arguments to bypass authentication mechanisms and inject operating system commands.

Affected Versions

All AhsayCBS versions up to 10.3.2 were confirmed as affected. Huntress reported on Thursday that threat actors have actively exploited these vulnerabilities in real-world attacks, with the latest version, 10.3.4, also impacted.

According to Huntress, exploit code targeting the flaws had been publicly released by the National Institute of Standards and Technology (NIST) on October 4.

Attack Details and Exploitation

Exploitation in the Wild

Attackers are combining the two flaws to gain unauthorized access to vulnerable systems and execute arbitrary code. As of October 8, at least five organizations have been targeted. Huntress observed that threat actors are using the vulnerabilities to achieve unauthenticated RCE and deploy webshells on exposed systems.

Attack Chain Details

CVE-2026-105134 allows unauthenticated RCE with system-level privileges via the Replication Receiver component’s API. The API contains an authentication bypass vulnerability, enabling attackers to substitute valid credentials with random tokens. Following exploitation, adversaries configured a malicious receiver and injected a Java Server Page (JSP) webshell into the CBS application’s directory.

According to Huntress, attackers also deployed XMRig cryptominers disguised as Microsoft Edge components and implemented an AI-assisted PowerShell script to monitor Task Manager.

Impact and Attack Methods

Malignant Activities

Once inside, attackers performed reconnaissance and deployed XMRig cryptominers disguised as Microsoft Edge components. They also implemented an AI-assisted PowerShell script to monitor Task Manager and terminate it if it remains active for extended periods.

Persistence Mechanisms

To maintain persistence, the attackers created a Windows service mimicking Microsoft Edge Update, using a modified version of the legitimate NSSM utility named msedge.exe with System privileges. In one instance, attackers utilized the legitimate but vulnerable kernel driver WinRing0x64.sys to grant the cryptocurrency miner kernel-level access.

Recommendations for Organizations

Immediate Mitigation Steps

Huntress advises restricting access to the management interface until a patch is available and conducting thorough compromise investigations. The firm recommends restricting access to trusted IP addresses or requiring a virtual private network (VPN) for external connections.

Security Best Practices

Organizations are urged to review their AhsayCBS configurations, monitor for signs of compromise, and apply available patches as soon as they become available. The incident underscores the criticality of securing management interfaces and addressing zero-day exploits promptly to prevent exploitation.

Conclusion

The vulnerabilities highlight the risks associated with unpatched systems and the importance of proactive security controls. Organizations must prioritize securing management interfaces and implementing robust mitigation strategies to defend against emerging threats.



About Author

en_USEnglish