A Severe Vulnerability in AhsayCBS Backup Solution Exposes Organizations to Remote Code Execution
Cybersecurity firm Huntress has warned that hackers are actively exploiting two unpatched vulnerabilities in the popular AhsayCBS backup solution, allowing them to inject malicious code and gain control over systems. This vulnerability affects not only older versions of the software but also the latest release, making it a pressing concern for organizations that rely on AhsayCBS for data protection.
AhsayCBS is a centralized cloud backup server management console developed by Ahsay Systems, widely used among managed service providers (MSPs) and system integrators. The exploited vulnerabilities, tracked as CVE-2026-105133 and CVE-2026-105134, enable attackers to manipulate arguments in certain functions of the tool, effectively bypassing authentication and injecting operating system commands.
According to Huntress, threat actors are chaining these two bugs to access vulnerable systems and execute arbitrary code on them. As of October 8, at least five organizations had been targeted by this exploit. Once inside, hackers conducted reconnaissance, deployed cryptocurrency miners disguised as Microsoft Edge, planted AI-assisted PowerShell scripts to monitor Task Manager, and created a Windows service masquerading as an update for the browser.
The exploitation process is straightforward: attackers inject malicious code into the vulnerable system using the manipulated functions in AhsayCBS. This allows them to execute arbitrary commands with System privileges, giving them complete control over the system. The most disturbing aspect of this exploit is its simplicity and the fact that it doesn’t require any user interaction.
Huntress has warned that organizations should restrict access to the management interface of AhsayCBS until a patch becomes available. They also recommend investigating systems for signs of compromise, as the attackers are likely to attempt to maintain persistence using techniques like creating Windows services or kernel-level drivers.
In one particularly concerning instance, hackers deployed WinRing0x64.sys, a legitimate but vulnerable kernel driver that enabled the cryptocurrency miner to operate with kernel-level access. This highlights the importance of keeping software up-to-date and implementing robust security measures to prevent such exploits from succeeding.
To protect themselves, organizations should limit access to the AhsayCBS management interface web app service on the host and require VPN or restrict access to trusted IP addresses only. Huntress also advises against using AhsayCBS until a patch is released, which could take some time given the complexity of the software.
In conclusion, this vulnerability serves as a stark reminder of the importance of maintaining up-to-date systems and implementing robust security measures. Organizations that rely on AhsayCBS for data protection must act swiftly to restrict access to the management interface and investigate their systems for signs of compromise.
Source: SecurityWeek — 2026-10-09