Hackers Exploit Two Unpatched AhsayCBS Vulnerabilities in the Wild
Huntress warns that attackers are exploiting CVE-2026-105133 and CVE-2026-105134 in the AhsayCBS backup solution for remote code execution. All versions up to 10.3.4 are affected with no patch available, and at least five organizations had been targeted as of October 8.
- CVE-2026-105133 and CVE-2026-105134 allow authentication bypass and OS command injection
- All AhsayCBS versions up to the latest 10.3.4 are affected, with no patch released
- Attackers deploy JSP webshells and XMRig cryptominers disguised as Microsoft Edge
- Huntress advises restricting management interface access and checking for compromise
Read next
Security