Huntress is seeing live attacks against AhsayCBS, the backup console used by many managed service providers. Two flaws, CVE-2026-105133 and CVE-2026-105134, are being chained for unauthenticated remote code execution. There is no fix through version 10.3.4.
What happened
The bugs were disclosed on 4 October 2026. Huntress saw exploitation start at 23:20 UTC on 7 October. By 8 October, at least five organizations had been targeted.
CVE-2026-105133 is an authentication weakness in the checkSysPwd function. CVE-2026-105134 sits in the Replication Receiver API. A random token can stand in for valid credentials, and the result is code execution as NT AUTHORITY\SYSTEM.
After access, attackers dropped JSP webshells, pulled tools from an object-storage host, and ran an XMRig miner renamed to look like Microsoft Edge. In one case they loaded the vulnerable WinRing0 kernel driver so the miner could touch hardware directly. A PowerShell script watches Task Manager and stops the fake update service while it is open.
Who is affected
AhsayCBS through 10.3.4 is affected. Huntress first thought 10.3.4 was safe, then confirmed it is not. The product is common at MSPs and system integrators because it is the central console for backup policy, storage, and users.
- Internet-exposed management interfaces are the target. The exploit hits the web app served by the CBS service process.
- A compromised console is a path into client backup infrastructure, not just the management host.
- Look for unexpected child processes of cbssvcX64.exe, a service named MicrosoftEdgeUpdateSvc, and files named edge.exe or msedge.exe in a Temp folder.
What to do now
Take the AhsayCBS management interface off the internet today. Limit it to trusted addresses or a VPN, and treat any exposed host as suspect until you prove otherwise.
- Do not wait on 10.3.4 or an earlier build. Huntress says those versions are still vulnerable.
- If you find the published indicators, re-image the host from a trusted backup. Huntress warned that attackers have hidden secondary backdoors.
- Check the client backup jobs this console controls. A webshell on the console is a supply-chain problem for every tenant on it.
Source: Huntress, Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer.
Also on the blog
- CVE-2026-107406: NetScaler SAML RCE at CVSS 9.5
- CVE-2026-21589: Atlassian Data Center file read at CVSS 9.3
- FBI seizes 7 Flax Typhoon domains used for Microscan and FishHub
- CVE-2026-106126: Tenable Identity Exposure SYSTEM injection, CVSS 9.9
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.