Attackers exploit unpatched AhsayCBS bugs for webshells and cryptomining

Threat actors are chaining two unpatched vulnerabilities in AhsayCBS, an authentication bypass and an OS command injection flaw, to compromise systems. Huntress observed attackers deploying JSP webshells and an XMRig miner disguised as edge.exe, with persistence through a service and a PowerShell script that hides mining activity. The flaws were reported fixed in version 10.3.2 but also affect the latest 10.3.4 release, and no patch was available at publication.
AhsayCBS is backup management software often used by managed service providers and system integrators. The exploited flaws are CVE-2026-105133, an authentication bypass with a public exploit, and CVE-2026-105134, an OS command injection issue. Although listed as fixed in 10.3.2, Huntress found both still affect 10.3.4, the newest release. Attacks observed October 7 hit at least five organizations.
After bypassing login and achieving command execution, intruders conducted reconnaissance, placed JSP webshells, and fetched XMRig renamed edge.exe. Persistence involved a service called MicrosoftEdgeUpdateSvc running a modified NSSM copy as msedge.exe. A PowerShell script, Taskgmr.ps1, allegedly AI-assisted, paused mining when Task Manager opened and stopped Task Manager at 6 p.m. or after an hour overnight. One victim also had WinRing0x64.sys deployed.
Because AhsayCBS is used by MSPs and integrators, compromised instances could expose not only the provider but also downstream client systems and backup data. Attackers may use webshells and miners to consume resources, maintain access, or disrupt recovery operations. Organizations relying on affected backups could face service interruptions, higher remediation costs, and potential data-restoration challenges. Until patched, limiting management interface access and restoring from clean backups may reduce risk.