Critical Vulnerabilities in AhsayCBS Exploited for Remote Code Execution
Article Content
- •Two critical vulnerabilities in AhsayCBS have been actively exploited since October 7, 2026.
- •CVE-2026-105134 allows unauthenticated remote code execution, enabling webshell deployment.
- •Organizations are advised to upgrade to version 10.3.4 to mitigate these vulnerabilities.
Huntress reports that threat actors are exploiting two critical vulnerabilities in AhsayCBS, a cloud backup server used by managed service providers. The vulnerabilities, CVE-2026-105133 and CVE-2026-105134, were published on October 4, 2026. CVE-2026-105133 allows for improper authentication, while CVE-2026-105134 enables unauthenticated remote code execution. Attackers are chaining these vulnerabilities to deploy webshells and XMRig cryptominers on compromised systems. The exploitation began on October 7, 2026, with suspicious activities observed from AhsayCBS executable files. A patch was released on August 5, 2026, to mitigate these issues. Organizations using AhsayCBS are urged to upgrade to version 10.3.4 to protect against these threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track XMRig and CVE-2026-105133 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of AhsayCBS are affected?
Is there a patch available?
What should organizations do now?
Continue Reading
Human Attacker Exploits Marimo RCE at Machine Speed A human attacker exploited CVE-2026-39987, a pre-authentication remote code execution vulnerability in Marimo notebooks, achieving a rapid transition from an open WebSocket to SSH access in just eight seconds. The attacker utilized a hand-rolled Python toolkit, bypassing detection mechanisms designed for AI-driven…
PoeLLM Malware Compromises 3,400+ AI Servers via GitHub Poem The PoeLLM malware campaign, tracked by Lumen Technologies' Black Lotus Labs, has infected over 3,400 servers since April 2026, primarily targeting exposed AI services like LiteLLM and Ollama. The malware cleverly hides its command-and-control (C2) server addresses within a poem posted on GitHub, allowing attackers to…