Skip to content
Critical Vulnerabilities in AhsayCBS Exploited for Remote Code Execution

Critical Vulnerabilities in AhsayCBS Exploited for Remote Code Execution

First seen 8 Oct 2026, 22:35 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 8, 2026 at 23:42 UTC
  • •Two critical vulnerabilities in AhsayCBS have been actively exploited since October 7, 2026.
  • •CVE-2026-105134 allows unauthenticated remote code execution, enabling webshell deployment.
  • •Organizations are advised to upgrade to version 10.3.4 to mitigate these vulnerabilities.

Huntress reports that threat actors are exploiting two critical vulnerabilities in AhsayCBS, a cloud backup server used by managed service providers. The vulnerabilities, CVE-2026-105133 and CVE-2026-105134, were published on October 4, 2026. CVE-2026-105133 allows for improper authentication, while CVE-2026-105134 enables unauthenticated remote code execution. Attackers are chaining these vulnerabilities to deploy webshells and XMRig cryptominers on compromised systems. The exploitation began on October 7, 2026, with suspicious activities observed from AhsayCBS executable files. A patch was released on August 5, 2026, to mitigate these issues. Organizations using AhsayCBS are urged to upgrade to version 10.3.4 to protect against these threats.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-04
CVE-2026-105133 and CVE-2026-105134 published
Two vulnerabilities in AhsayCBS were disclosed, with CVE-2026-105134 rated critical for remote code execution.
Huntress
2026-10-05
First public PoC for CVE-2026-105134
Proof-of-concept code for the critical vulnerability was published, raising concerns about potential exploitation.
X
2026-10-07
Active exploitation observed
Huntress reported that threat actors began exploiting the vulnerabilities to execute code and deploy webshells.
Huntress

More articles in this cluster (5)

Following this threat?

Track XMRig and CVE-2026-105133 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of AhsayCBS are affected?
AhsayCBS versions up to 10.3.2 are affected by the vulnerabilities.
Is there a patch available?
Yes, Ahsay released version 10.3.4 on August 5, 2026, which mitigates the vulnerabilities.
What should organizations do now?
Organizations should upgrade to version 10.3.4 immediately to protect against exploitation.