At a glance:
-
Researchers reported active exploitation of two AhsayCBS vulnerabilities on October 8 after identifying attacks that began a day earlier. Affected systems can be compromised without valid credentials.
-
The vulnerabilities can be chained by a remote, unauthenticated threat actor to execute commands with SYSTEM privileges on exposed AhsayCBS servers.
-
Review AhsayCBS deployments, limit exposure of management interfaces, and investigate affected servers for web shells, unauthorized services, and cryptomining activity.
Threat summary
On October 8, 2026, researchers reported active exploitation of two vulnerabilities affecting Ahsay Cloud Backup Server (AhsayCBS), a centralized platform used to manage backup operations, storage locations, user accounts, policies, and replication services. Exploitation activity was first observed late October 7, and researchers identified five affected organizations within the first day of reporting. Public proof-of-concept exploit code was available when the vulnerabilities were disclosed.
One of the affected components is the Replication Receiver service, which allows backup servers to receive replicated data from other systems. Administrators use associated application programming interfaces (APIs) to configure replication settings and manage trusted replication partners.
The two actively exploited vulnerabilities are:
- CVE-2026-105133, an improper authentication vulnerability in the checkSysPwd function with a Common Vulnerability Scoring System (CVSS) score of 5.5.
- CVE-2026-105134, an operating system command injection vulnerability in the Replication Receiver component with a CVSS score of 9.3.
Researchers demonstrated that an adversary could combine the two flaws to gain unauthenticated access, configure a malicious replication receiver, deploy a Java Server Pages (JSP) web shell, and execute commands with NT AUTHORITY\SYSTEM privileges. Exploitation depends on network access to a vulnerable AhsayCBS interface.
Threat actors have been using the vulnerabilities to deploy web shells, conduct reconnaissance, and install XMRig cryptocurrency miners disguised as Microsoft Edge processes. Additional activity included the creation of a fake Edge update service for persistence and PowerShell scripts intended to conceal mining activity. While observed attacks focused on cryptomining, the demonstrated access creates opportunities for broader post-compromise activity depending on how the environment is configured.
Analysis
For most organizations, compromise of an AhsayCBS server creates risk to both the server itself and the backup infrastructure it manages. The risk is greater in environments where a single AhsayCBS deployment manages backups across multiple customers, locations, or business units because the platform serves as a central administration point for those environments.
Researchers demonstrated SYSTEM-level access to the underlying Windows server, which effectively provides the same control as the operating system itself. A successful compromise could expose credentials, storage locations, backup repositories, and administrative functions available to the server.
The management server is often more valuable than the backup data it stores because it maintains connections to backup destinations, storage systems, domain services, and privileged service accounts. A compromise of the server may create a path to those connected resources depending on deployment architecture, configured integrations, and assigned permissions. The demonstrated access could be used for credential theft, backup manipulation, or additional intrusion activity, although researchers have not reported those actions in observed exploitation.
Internet-facing deployments warrant the highest priority because exploitation is remote and does not require valid credentials or user interaction. Researchers also reported that versions through 10.3.4 remained vulnerable at the time of disclosure, creating a risk that organizations believed affected systems had already been remediated when exposed deployments remained accessible.
This activity is also significant because backup management platforms play an important role during ransomware recovery and incident response. For defenders, the priority is identifying exposed AhsayCBS deployments, validating versions, and investigating for evidence of post-compromise activity rather than focusing solely on the cryptomining activity that has been observed so far.
Mitigations
Review all AhsayCBS deployments across production, disaster recovery, test, and secondary environments to identify exposed systems and determine affected versions. This establishes where investigation and remediation efforts are required.
Limit access to management interfaces and Replication Receiver services to trusted administrative networks, approved source addresses, or virtual private network (VPN) connections. Reducing external accessibility removes the direct attack path used in observed exploitation.
Upgrade affected systems to a vendor-fixed release when one becomes available.
Monitor for unexpected JSP files within application directories, suspicious child processes launched by cbssvcX64.exe, unauthorized receiver configurations, PowerShell activity, and outbound connections associated with cryptomining infrastructure. These activities align with observed exploitation behavior.
Investigate systems displaying indicators of compromise for unauthorized services, web shells, and persistence mechanisms. Rebuilding compromised hosts from known-good media and redeploying the application removes malicious changes that may remain after software updates.