Why it matters
Organizations running AhsayCBS should assess their exposure and prioritize remediation: attackers are exploiting its flaws to gain control and deploy webshells and cryptocurrency miners.
CVE-2026-105134
- Severity
- 10.0 Critical · CVSS 4.0 · VulDB
- Exploited
- Not in CISA’s catalog
- Published
- AhsayCBS
Affected: 10.3.0; 10.3.1; 10.3.2
Fixed: 10.3.4
ahsay.com · CVE record · NVD
CVE-2026-105133
- Severity
- 6.9 Medium · CVSS 4.0 · VulDB
- Exploited
- Not in CISA’s catalog
- Published
- AhsayCBS
Affected: 10.3.0; 10.3.1; 10.3.2
Fixed: 10.3.4
ahsay.com · CVE record · NVD
What we know
Confirmed by several sources
- Attackers are exploiting vulnerabilities in the AhsayCBS backup platform. — BleepingComputer, The Hacker News, SecurityWeek
- The attacks deploy webshells and cryptocurrency miners. — BleepingComputer, The Hacker News
Reported by one source
- The vulnerabilities are identified as CVE-2026-105133 and CVE-2026-105134. — SecurityWeek
- The flaws allow authentication bypass and OS command injection. — SecurityWeek
- XMRig miners are disguised as Microsoft Edge. — The Hacker News
- One vulnerability is critical and the other medium severity. — BleepingComputer
Coverage 3 publishers
SecurityWeekFirst report
Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands.
-
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below…
-
Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners.
Earliest report first. Articles stay on their publishers’ sites; each link opens the original.
