AhsayCBS Bugs Abused to Install XMRig Miners and Web Shells

Threat actors are exploiting two recently disclosed vulnerabilities in the AhsayCBS backup utility. The flaws let attackers seize affected devices and deploy web shells and XMRig cryptocurrency miners while disguising the activity as Microsoft Edge. One flaw, CVE-2026-105133, is an improper authentication issue in the checkSysPwd() function.
Two recently disclosed vulnerabilities in AhsayCBS, a backup utility, are being exploited by threat actors. The flaws permit attackers to seize affected devices. Once in control, they can deploy web shells and XMRig cryptocurrency miners, and they can disguise this activity as Microsoft Edge.
One flaw is CVE-2026-105133, described as an improper authentication issue in the checkSysPwd() function. The available information does not identify affected versions, patch availability, or the scope of exploitation. The case illustrates how backup software can become a target for both remote access and resource-hijacking attacks.
Organizations using AhsayCBS could face system compromise, resource abuse, or persistent access if the flaws are exploited. Because attackers may install web shells, compromised systems might remain accessible after initial intrusion. Cryptocurrency mining could consume computing resources and raise costs. The disguise as Microsoft Edge may complicate detection for defenders and users. The broader impact may extend to customers and partners whose data or services depend on affected backups.