Full Report
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. [...]
Analysis Summary
# Vulnerability: Unpatched Authentication Bypass and RCE in AhsayCBS
## CVE Details
- **CVE ID:** CVE-2026-105133
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-287 (Improper Authentication)
- **CVE ID:** CVE-2026-105134
- **CVSS Score:** 6.5 (Medium)
- **CWE:** CWE-78 (OS Command Injection)
## Affected Systems
- **Products:** AhsayCBS Backup Management Platform
- **Versions:** 10.3.2 and 10.3.4 (Latest version confirmed vulnerable despite initial fix reports)
- **Configurations:** Systems with the management interface exposed to the public internet.
## Vulnerability Description
Threat actors are chaining two vulnerabilities to achieve Remote Code Execution (RCE).
1. **CVE-2026-105133:** An authentication bypass flaw that allows an attacker to gain unauthorized access to the management console.
2. **CVE-2026-105134:** An OS command injection vulnerability. Once authenticated (or via the bypass above), an attacker can inject malicious commands into the underlying operating system.
## Exploitation
- **Status:** Exploited in the wild (active campaigns observed targeting at least five organizations).
- **Complexity:** Low (Public exploit code is available).
- **Attack Vector:** Network.
## Impact
- **Confidentiality:** High (Full access to backup management and data).
- **Integrity:** High (Ability to deploy webshells and modify system files).
- **Availability:** High (Deployment of resource-heavy miners and potential for system disruption).
## Remediation
### Patches
- **No Current Effective Patch:** While Ahsay reported these as fixed in version 10.3.2, researchers have confirmed that the current latest version (**10.3.4**) remains vulnerable. Users should monitor vendor updates for a definitive fix.
### Workarounds
- **IP Whitelisting:** Restrict access to the AhsayCBS management interface to trusted, known IP addresses only.
- **Network Isolation:** Ensure the backup management server is not directly accessible from the public internet; use a VPN for remote administration.
## Detection
### Indicators of Compromise
- **Files:**
- `edge.exe` (XMRig miner)
- `Taskgmr.ps1` (PowerShell script to hide mining activity)
- `WinRing0x64.sys` (Vulnerable driver used for hardware access)
- Presence of unexpected Java Server Page (`.jsp`) files in web directories.
- **Services:**
- `MicrosoftEdgeUpdateSvc` (Malicious service running a modified NSSM utility).
- **Behavior:**
- Automatic closing of Windows Task Manager at 6 p.m. or after 60 minutes of use.
- CPU spikes that disappear immediately when monitoring tools are opened.
### Detection methods and tools
- **Sigma Rules:** Huntress has released four specific Sigma rules for identifying this exploit chain.
- **Log Analysis:** Review AhsayCBS access logs for unusual source IPs and command injection attempts in web requests.
## References
- **Vendor Home:** hxxps[://]www[.]ahsay[.]com/
- **Huntress Research:** hxxps[://]www[.]huntress[.]com/blog/ahsaycbs-flaws-exploit
- **NVD Entries:**
- hxxps[://]nvd[.]nist[.]gov/vuln/detail/cve-2026-105133
- hxxps[://]nvd[.]nist[.]gov/vuln/detail/cve-2026-105134