Attackers are chaining two unpatched security flaws in Ahsay Systems’ AhsayCBS cloud backup management platform to bypass authentication and execute arbitrary operating system commands with elevated system privileges. The attacks jeopardize backup servers widely utilized by managed service providers and systems integrators to oversee client policies, storage, and user credentials.
The flaws are tracked as CVE-2026-105133, an authentication bypass defect, and CVE-2026-105134, an operating system command injection vulnerability. SecurityWeek reports that both issues were disclosed on October 4, accompanied by a warning from NIST that public exploit code was circulating and affected versions up to 10.3.2. While the flaws were reported as fixed in version 10.3.2, managed detection and response firm Huntress discovered that the latest release, AhsayCBS 10.3.4, remains vulnerable to the exploits.
According to findings by Huntress, attackers chain the flaws to manipulate tool function arguments and achieve remote code execution without authentication. Threat actors breach an API within the Replication Receiver component using a random token in place of legitimate credentials, allow the creation of a rogue receiver, and drop a Java Server Page webshell directly into the central application directory.
Once inside the server, attackers perform reconnaissance and establish persistence using disguised system components. BleepingComputer reports that the intruders install XMRig cryptocurrency miners masked under executable names like edge.exe. To maintain persistence, the perpetrators register a Windows service named “MicrosoftEdgeUpdateSvc” running msedge.exe, which Huntress identified as a modified version of the Non-Sucking Service Manager utility operating with System privileges. In at least one compromise, the attackers deployed the vulnerable WinRing0x64.sys driver to obtain kernel-level access and unlock hardware resources for mining.
The intrusion campaign also conceals active processes using a PowerShell script labeled Taskgmr.ps1, which Huntress researchers suspect was drafted with AI assistance. The script halts the mining service whenever Task Manager runs and starts it again once the diagnostic tool exits. The routine also automatically kills Task Manager at 6:00 p.m. local time or whenever the process stays open for more than an hour during overnight hours.
The attacks began targeting organizations on October 7, and Huntress verified that at least five entities had been targeted as of October 8. Security researchers advise network administrators to immediately isolate exposed AhsayCBS management web interfaces behind a VPN or whitelist access exclusively to trusted IP addresses. If intrusion activity is detected, Huntress warns that teams must restore systems from clean backups, as threat actors may leave hidden backdoors. Ahsay Systems has not yet commented on its remediation roadmap, and official security patches remain unreleased.

