Vulnerabilities

Unpatched AhsayCBS flaws exploited to hijack MSP backup servers

Attackers chain two AhsayCBS flaws for SYSTEM-level code execution on MSP backup servers. Huntress says 10.3.4 is still vulnerable and no patch exists.

Illustration of a backup server with a warning symbol, representing unpatched AhsayCBS vulnerabilities under active exploitation

Attackers are chaining two AhsayCBS vulnerabilities to take over the backup management servers that many managed service providers run for their customers. There is no fix: Huntress says the latest release is also vulnerable, so restricting network access is the only real defence for now.

What happened

Huntress has reported live exploitation of two flaws in AhsayCBS, the server-side console behind Ahsay’s backup products. The bugs are tracked as CVE-2026-105133 and CVE-2026-105134. The National Vulnerability Database published both records on 4 October 2026, and they note that exploit code was already public. Huntress first saw attackers using them at 23:20 UTC on 7 October. By the following day it had counted five targeted organisations, and it later told The Hacker News it had seen one more incident using the same techniques. It added that there was no sign of broader exploitation.

The more serious problem is the patch status. The NVD entries, which came from the CVE numbering authority VulDB, describe the flaws as affecting releases up to 10.3.2 and say that upgrading to 10.3.4 resolves them. On the evening of 8 October, Huntress updated its analysis to say that 10.3.4 is also exploitable. Ahsay’s own release notes for 10.3.4, dated 5 August 2026, list feature changes and bug fixes but no security fixes, and the release-notes index shows nothing newer. If Huntress is right, there is no fixed release yet, so every exposed instance is at risk until Ahsay ships one. BleepingComputer said it had asked Ahsay about its plans for a fix but had no reply by the time it published. When I checked on 11 October, neither CVE was in CISA’s Known Exploited Vulnerabilities catalogue.

The technical picture

The attack uses two bugs together. CVE-2026-105133 has a CVSS v4 score of 5.5. It sits in the checkSysPwd function of the AhsayCBS API, and an attacker can satisfy the authentication check by supplying a manipulated value. That weakness is then used to reach CVE-2026-105134, rated 9.3. That flaw is in the UpdateReceivers endpoint of the Replication Receiver component, which NVD classes as operating system command injection. The combined result is unauthenticated remote code execution with SYSTEM privileges on Windows hosts.

The medium score on the first CVE could easily mislead a triage team that ranks work purely by CVSS. On its own, it looks like a modest authentication issue. Chained with the second flaw, it opens the whole server to anyone who can reach the management interface over the network.

The post-exploitation activity Huntress observed has been opportunistic rather than sophisticated. In some cases the attackers planted JSP webshells in the directory the CBS web application serves. In others, the AhsayCBS service process downloaded files from Alibaba Cloud object storage. These included an XMRig Monero miner renamed edge.exe and a modified copy of the NSSM service manager renamed msedge.exe. The attackers registered a Windows service called MicrosoftEdgeUpdateSvc, a name close enough to the genuine Edge updater to pass a quick look, to keep the miner running as SYSTEM. A PowerShell script, which Huntress believes was written with help from an AI tool, paused the miner whenever Task Manager was opened and shut Task Manager down at 18:00, or after an hour of overnight use. In one intrusion the attackers also loaded WinRing0x64.sys, a legitimate but vulnerable driver, to give the miner direct access to the hardware.

Flow diagram of the AhsayCBS attack chain, from authentication bypass and command injection to webshell, fake Edge service and hidden cryptominer

Why it matters for UK organisations

None of the sources has named UK victims, and I will not speculate about any. The UK exposure comes through the supply chain. Huntress describes AhsayCBS as mainly used by managed service providers and system integrators, which use it to run backup operations for many client organisations from one console. Ahsay supports rebranded installers, so a UK business buying backup from a local provider may not know Ahsay is underneath.

Mining is the least harmful use of this access. The same foothold gives access to backup credentials, retention policies, storage targets and, often, connections into customer environments. Ransomware groups have long gone after backups first, because deleting restore points makes victims pay. A more patient group could use the same entry point very differently. Huntress warns that attackers may have left additional backdoors, which is why it advises rebuilding any compromised host rather than cleaning it.

Managed service providers are an attractive way into many organisations at once, and this case shows why. An MSP running AhsayCBS with its management interface exposed to the internet puts every customer it serves at risk.

Expert view

In my experience, backup infrastructure is one of the least scrutinised parts of most estates. Nobody thinks about it until a restore fails. When we test MSP environments, the backup management console is often reachable from the internet because remote technicians and customer self-service portals were given priority over exposure. That convenience is exactly what this campaign relies on.

The patching story is the part that should worry people most. A vulnerability record that says a version fixes the problem, followed days later by a researcher showing that version is still vulnerable, is a trap for anyone who simply checks version numbers against an advisory. Scanners that rely on NVD version data may wrongly report hosts that were upgraded to 10.3.4 in good faith as safe.

I would also be wary of the crypto-mining. Noisy miners are often the first wave on a newly public bug, not the last. The mining payload tells you the door is open. It tells you nothing about who else has already walked through it.

What to do now

  1. Find every AhsayCBS instance. MSPs should check their own estate and any customer-hosted deployments. Customers should ask their backup provider directly whether Ahsay sits behind the service.
  2. Take the management interface off the internet. Allow access only from trusted IP addresses or through a VPN, as Huntress recommends. This is the firewall and boundary control in Cyber Essentials, and right now it is the main mitigation available.
  3. Do not rely on version 10.3.4. Treat all releases as vulnerable until Ahsay publishes a fix and an advisory, then apply it quickly in line with the security update management control.
  4. Hunt for compromise. Look for unexpected child processes of cbssvcX64.exe, a service named MicrosoftEdgeUpdateSvc, Edge-named binaries in Temp folders, JSP files in the CBS web directory, outbound connections on port 8029 and any trace of WinRing0x64.sys. Huntress has published indicators and four Sigma rules.
  5. Rebuild, do not clean. If you find indicators, re-image the host from a known good backup and rotate every credential the backup server held, including storage and cloud keys.
  6. Check backup integrity and isolation. Confirm that immutable or offline copies exist and have not been changed, and that the backup server’s privileges in customer networks are as limited as they can be.

Bottom line

This is an actively exploited, unauthenticated remote code execution chain in a product built to protect other people’s data, and there is no working patch. For UK MSPs running Ahsay, the job this weekend is simple: get the console off the public internet, check for compromise, and tell your customers what you have done. Customers of those MSPs should be asking that question first thing on Monday.

Sources