Cybersecurity experts are raising alarms over two critical vulnerabilities in the AhsayCBS backup solution that have been exploited for remote code execution (RCE). These vulnerabilities, identified as CVE-2026-105133 and CVE-2026-105134, have been actively targeted by threat actors, according to Huntress, a prominent cybersecurity firm.
Understanding the AhsayCBS Vulnerabilities
AhsayCBS, developed by Ahsay Systems, is widely used by managed service providers (MSPs) and system integrators for backup management. The software allows users to manage backup policies and storage effectively. However, it has recently come under scrutiny due to these unpatched security flaws that enable attackers to bypass authentication and execute unauthorized operating system commands.
The vulnerabilities were initially disclosed on October 4, with the National Institute of Standards and Technology (NIST) warning about available exploit code. All versions up to 10.3.2 were confirmed to be susceptible, and even the latest version, 10.3.4, remains vulnerable as per recent reports from Huntress.
Immediate Security Recommendations
Huntress advises organizations to take immediate precautions by restricting access to the AhsayCBS management interface. Until a patch is released, limiting access to trusted IP addresses or using a VPN is recommended to mitigate potential risks. The firm has observed multiple instances where attackers have chained these vulnerabilities to gain unauthorized access and deploy malicious webshells.
As of October 8, at least five organizations have been confirmed as targets of these exploits. The attackers utilized these flaws to execute arbitrary code, achieving unauthenticated remote code execution with system privileges through the platform’s Replication Receiver component.
Exploitation Techniques and Defensive Measures
The attackers also employed advanced techniques post-exploitation, including deploying XMRig cryptominers with kernel-level privileges. They used legitimate software, such as WinRing0x64.sys, to maintain persistence and avoid detection. Additionally, they created a Windows service disguised as Microsoft Edge Update to execute malicious scripts.
Organizations are urged to implement strict access controls and monitor their networks for signs of compromise. By limiting the exposure of the AhsayCBS management interface, companies can reduce the risk of these vulnerabilities being exploited in the wild.
In light of these developments, cybersecurity professionals emphasize the importance of regular updates and vigilance against potential threats. As the exploitation of these vulnerabilities continues, staying informed and proactive is crucial to safeguarding sensitive data.
