Backup Server, Attacker Server: AhsayCBS Zero-Days CVE-2026-105133 and CVE-2026-105134 Chained to SYSTEM Webshells and XMRig
Starting at 23:20:15 UTC on 7 October 2026, Huntress analysts watched threat actors chain two freshly disclosed AhsayCBS flaws into unauthenticated remote code execution as NT AUTHORITY\SYSTEM on internet-exposed backup servers. By the next day, five organisations were hit. The two CVEs had landed in NVD only three days earlier, on 4 October — and as of 10 October there is still no patch, with the latest release, 10.3.4, confirmed vulnerable. Huntress published its writeup on 8 October (Dray Agha, Olly Maxwell, Tyler Bohlmann, Amelia Casley), Field Effect confirmed the activity in an 9 October intelligence report, and BleepingComputer reports Ahsay has not responded to requests about its fix plans.
The pair, per the NVD records: CVE-2026-105133, an improper-authentication flaw in the checkSysPwd function (com/ahsay/obs/api/ApiStructsAction.java), CVSS 4.0 5.5 Medium — the weak-looking half that does the heavy lifting; and CVE-2026-105134, operating-system command injection in the Replication Receiver endpoint /rps/api/json/UpdateReceivers.do, CVSS 4.0 9.3 Critical (CVSS 3.1 10.0). Both NVD records sit at status Deferred with secondary-only scoring and exploit maturity already marked E:P — proof-of-concept code was public at disclosure. The API contains an authentication bypass that lets a random token substitute for valid credentials; the attacker then configures a malicious replication receiver and drops a JSP webshell into a directory the CBS application itself serves. First the 5.5 opens the door, then the 9.3 walks through it with SYSTEM privileges.
What the attackers did with SYSTEM
Huntress traces the campaign from suspicious child processes spawning out of cbssvcX64.exe — the webshell's commands surface as direct children of the service, which is itself a detection anchor. Post-exploitation followed a now-familiar playbook with a few notable flourishes: reconnaissance, JSP webshells, then an XMRig Monero miner (edge.exe) staged from Alibaba Cloud object storage alongside a renamed NSSM persistence utility (msedge.exe), installed as a Windows service called MicrosoftEdgeUpdateSvc — one letter off the legitimate Edge updater — running as SYSTEM. Mining traffic went to a Kryptex pool (xmr.kryptex[.]network:8029, pool user krxYMRN97D/creativejs).
Two details deserve attention beyond the mining. The first is Taskgmr.ps1, a PowerShell script Huntress describes as apparently AI-assisted from its commented code: it continuously watches for Task Manager, stops the mining service while it is open, restarts it on close — and kills Task Manager outright at 18:00 local time or if left open over an hour overnight. Commodity tradecraft, possibly machine-drafted, doing the hiding work automatically. The second is the deployment of the known-vulnerable WinRing0x64.sys driver via certutil.exe — not, in Huntress's reading, to blind EDR this time, but to give the miner kernel-level access to the hardware for maximum hash rate. Bring-your-own-vulnerable-driver repurposed from defense evasion to mining performance is a small evolution worth noting.
Why backup infrastructure is the worst place for this
Field Effect's report makes the structural point: AhsayCBS is the central administration point for backup operations — users, policies, storage locations, replication — and it is concentrated in MSPs and system integrators, where one deployment manages backups across multiple customers. Huntress adds that SYSTEM on the management server exposes credentials, repositories, and administrative functions, with a path into connected storage, domain services, and privileged service accounts. And the platform's role in ransomware recovery is what elevates this above a cryptomining nuisance: the observed payload is miners today, but the demonstrated access — webshell, SYSTEM service, secondary backdoors — is whatever the next operator wants it to be, sitting on the exact infrastructure you would reach for after a ransomware event. Huntress is explicit that confirmed compromises need a full host re-image from trusted backup, because secondary backdoors outlive software updates.
Three versioning facts compound the risk. First, advisories initially described the flaws as fixed in 10.3.2 — Huntress's 8 October 6pm ET update corrected that: 10.3.4 is also affected, so anyone who “patched” to latest is still exposed. Second, this is the same shape we covered in the NetScaler CVE-2026-107406 bulletin — the fixed build becoming the affected range — except here there is no fixed build at all. Third, neither CVE appears in CISA's KEV catalog (1,739 entries, checked 10 October), which is a statement about catalog lag, not about safety: exploitation is confirmed, public, and ongoing.
What to do
- Remove the attack path now: restrict the management interface. No patch exists. Limit AhsayCBS web and Replication Receiver access to trusted IPs or VPN-only, per Huntress and Field Effect. Internet-facing deployments are the priority — exploitation needs no credentials and no user interaction.
- Hunt for the campaign's fingerprints. Unexpected child processes of
cbssvcX64.exe/cbssvcX86.exe, unfamiliar.jspfiles in application directories, unauthorised receiver configurations, Edge-named binaries running with daemon flags, Task-Manager-aware PowerShell, and WinRing0 fetched by URL. Huntress published four Sigma rules (path2026/2026-10/AhsayCBS_XMRig_Minerin its threat-intel repo) ordered to the intrusion chain. - Re-image confirmed compromises from known-good media. Do not trust an in-place cleanup: the actor plants secondary persistence (spoofed updater service, webshells). Rebuild the host, redeploy the application, then rotate every credential and storage secret the server touched.
- Inventory every AhsayCBS instance, including the forgotten ones. Field Effect specifically calls out DR, test, and secondary environments. A backup console nobody remembers is still a SYSTEM shell for anyone who finds it — and it guards the recovery path for everything else.
Verification note: the exploitation start time (7 October 2026 23:20:15 UTC), five targeted organisations, attack chain (random-token auth bypass via CVE-2026-105133, SYSTEM RCE via CVE-2026-105134 against /rps/api/json/UpdateReceivers.do, malicious receiver plus JSP webshell), post-exploitation details (XMRig edge.exe, NSSM msedge.exe with SHA-256 hashes, MicrosoftEdgeUpdateSvc, Taskgmr.ps1 behaviour and hash, WinRing0x64.sys via certutil, Kryptex pool host, port, and pool user, Alibaba OSS staging URLs, four Sigma rules, MITRE mapping), the 10.3.4-affected correction, and the no-patch status were read first-hand from the Huntress blog HTML fetched on 10 October 2026. CVE numbers, NVD publication date (4 October 2026), Deferred status, CVSS 4.0 scores (5.5 / 9.3) and vectors, CVSS 3.1 scores (7.3 / 10.0), affected files, and E:P exploit maturity were retrieved from the NVD 2.0 API the same day. Field Effect’s 9 October report (public PoC at disclosure, five organisations in the first day, backup-recovery framing) and BleepingComputer’s account (Ahsay non-response, AI-assisted script characterisation) were fetched first-hand and are attributed accordingly. KEV absence was checked against CISA’s published CSV (1,739 entries) on 10 October 2026. We tested nothing and exploited nothing.
Sources:
- Huntress — Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer (8 October 2026; primary investigation, IoCs, Sigma rules, MITRE mapping)
- NVD — CVE-2026-105133 (published 4 October 2026, Deferred, CVSS 4.0 5.5, checkSysPwd improper authentication)
- NVD — CVE-2026-105134 (published 4 October 2026, Deferred, CVSS 4.0 9.3 / 3.1 10.0, Replication Receiver command injection)
- Field Effect — Threat Actors Exploit AhsayCBS Zero-Days (9 October 2026; exploitation timeline, backup-recovery risk framing)
- BleepingComputer — Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto (9 October 2026; 10.3.4 affected, vendor non-response)
- CISA — Known Exploited Vulnerabilities catalog (CSV, 1,739 entries; neither CVE listed as of 10 October 2026)