Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

A severe vulnerability in the AhsayCBS backup solution has been exploited by hackers in the wild, putting thousands of organizations at risk. Cybersecurity firm Huntress has confirmed that two unpatched flaws, tracked as CVE-2026-105133 and CVE-2026-105134, have been targeted by attackers to gain remote code execution (RCE) on vulnerable systems.

AhsayCBS is a popular cloud backup solution used by managed service providers (MSPs) and system integrators. The platform provides centralized management of backups, storage, and user access. However, the two vulnerabilities discovered in AhsayCBS allow attackers to bypass authentication and inject operating system commands, enabling them to execute arbitrary code on vulnerable systems.

The flaws were disclosed on October 4 by NIST, warning that exploit code targeting them had been released, and that all AhsayCBS versions up to 10.3.2 were affected. But, in a disturbing turn of events, Huntress has now confirmed that attackers have exploited the vulnerabilities in the wild, with at least five organizations targeted as of October 8.

According to Huntress, threat actors are chaining the two bugs to access vulnerable systems and execute arbitrary code on them. The exploitation process involves manipulating arguments in certain functions of the tool to bypass authentication and inject OS commands. In one attack, hackers deployed a webshell on exposed systems, while in another, they used an AI-assisted PowerShell script to monitor Task Manager and terminate it if it remained open for too long.

Furthermore, attackers have also achieved persistence by creating a Windows service masquerading as Microsoft Edge Update, which executes a modified copy of the legitimate NSSM utility named msedge.exe with System privileges. This is particularly concerning, as it enables threat actors to maintain persistence on affected systems while disguising their malicious activity as legitimate system processes.

To mitigate this risk, Huntress recommends restricting access to the AhsayCBS management interface and investigating for signs of compromise until a patch is available. Organizations should also limit access to trusted IP addresses only or require VPN, and ensure that the externally accessible web app service on the host is restricted.

The exploitation of these vulnerabilities highlights the importance of regular security updates and patching. It’s essential for organizations using AhsayCBS to apply the latest patches as soon as possible and monitor their systems for any signs of compromise. By taking proactive measures, businesses can minimize the risk of falling victim to these attacks and protect their sensitive data from malicious actors.


Source: SecurityWeek — 2026-10-09