Two critical vulnerabilities in AhsayCBS backup management software are being actively exploited. Since October 7, 2026, Huntress has observed threat actors targeting at least five organizations, deploying webshells and cryptocurrency miners on exposed backup servers. The flaws, CVE-2026-105133 and CVE-2026-105134, allow unauthenticated remote code execution with SYSTEM privileges, and the attack chain requires no user interaction. AhsayCBS is popular with managed service providers (MSPs) and system integrators, which means a single compromised backup console can be a foothold into the networks of every client the provider serves.

The vulnerabilities were disclosed on October 4, 2026. SecurityWeek reports that NIST warned exploit code had already been released at the time of disclosure. Three days later, real attacks began. Organizations running AhsayCBS should assume the exploit is now widely available and act accordingly.

What exactly is AhsayCBS, and who uses it?

AhsayCBS (Cloud Backup Server) is a centralized management console for Ahsay's backup software, used primarily by MSPs and system integrators. It lets administrators create users, configure backup policies, manage storage, and oversee backup operations across client environments. Huntress describes it as the management console that "centralizes control of backup operations." Because it often connects to multiple client environments, a compromised AhsayCBS server can give attackers a path into every organization the MSP serves. If you work with an MSP or IT provider, this may be running on their infrastructure on your behalf.

How are attackers exploiting these vulnerabilities?

Attackers are chaining two vulnerabilities together. According to Huntress, CVE-2026-105133 bypasses authentication, and CVE-2026-105134 enables unauthenticated remote code execution as NT AUTHORITY/SYSTEM through the Replication Receiver component. The CVE record rates CVE-2026-105134 at CVSS 4.0 score of 10.0, which is the maximum severity. BleepingComputer confirmed that attackers "chained the two vulnerabilities, CVE-2026-105133 first to bypass authentication and then CVE-2026-105134 for code execution."

Post-exploitation, attackers deploy Java Server Page (JSP) webshells into the application directory and download additional payloads. The attack requires only that the management interface be reachable over the network. No credentials are needed.

What are attackers doing on compromised servers?

So far, all observed intrusions have focused on cryptomining. According to BleepingComputer, attackers deployed XMRig miners disguised as Microsoft Edge processes (edge.exe) and created a fake Windows service called MicrosoftEdgeUpdateSvc to maintain persistence. Huntress also observed a PowerShell script that monitors Windows Task Manager and shuts it down if it stays open too long, presumably to hide the cryptomining activity from anyone checking system resources.

That said, SYSTEM-level access opens far worse possibilities. Huntress Support notes: "because the attackers achieve SYSTEM-level privileges, data compromise cannot be entirely ruled out." The same access could be used for credential theft, backup manipulation, or as a launch point for ransomware. Those scenarios are potential rather than observed, but they are why security researchers are treating this seriously.

Which AhsayCBS versions are vulnerable?

The CVE record for CVE-2026-105134 lists versions 10.3.0, 10.3.1, and 10.3.2 as affected and version 10.3.4 as unaffected. Ahsay's October 9 statement says version 10.3.4.0, released on August 4, 2026, "addressed" both vulnerabilities and that "partners who have already upgraded to v10.3.4.0 are no longer affected."

However, Huntress disputes this. In an October 8 update, Huntress stated: "After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities." Until this discrepancy is resolved, the safest approach is to restrict management interface access regardless of which version you run.

What should organizations do right now?

The immediate priority is network segmentation. SecurityWeek reports that Huntress recommends "restricting access to the management interface and investigating for signs of compromise." The exploit targets the externally accessible web application, so limiting access to trusted IP addresses or requiring a VPN removes the attack surface entirely while the patching situation is clarified.

  1. Restrict web access to the AhsayCBS management interface immediately. Allow only trusted IP addresses or require VPN.
  2. Upgrade to version 10.3.4.0 if not already current. Ahsay says this version fixes both CVEs.
  3. Investigate for compromise. Check for the indicators of compromise (IoCs) Huntress published, including suspicious processes spawned from cbssvcX64.exe, unknown .jsp files in the web application directory, and the MicrosoftEdgeUpdateSvc service.
  4. Re-image if compromised. If any IoCs are present, perform a full host re-image from a known-clean backup. Huntress warns that "upgrading an already-compromised server will not remove webshells or malicious configurations."

For guidance on whether your backup strategy would actually let you recover from a compromise like this, see our overview of backup and recovery assumptions that often fail.

Why does a backup server compromise matter for SMBs?

A backup server is one of the highest-value targets an attacker can reach. It often contains credentials, sensitive data, and connections to multiple systems. For MSP customers, a compromised backup console may touch every client the provider serves. As we covered in our explanation of MSP vs. MSSP responsibilities, the line between your provider's infrastructure and yours can blur in an incident.

This attack also illustrates the speed at which exploitation now happens. Vulnerabilities disclosed on October 4 were being actively exploited by October 7. Our post on the shrinking CVE-to-exploit window covers why monthly patching cycles no longer keep pace with current threats.

What question should you ask your IT provider?

If you work with an MSP, ask: "Do you run AhsayCBS or any other backup management console that is internet-accessible, and if so, have you restricted access and checked for the October 7 indicators of compromise?" The answer tells you whether your provider is aware of this specific threat and whether they have acted on it. A good provider will already have restricted access or be able to explain why their configuration is not exposed.

What should US and Canadian businesses take from this?

This incident is a reminder that the tools meant to protect you can themselves become attack vectors. Backup software, security tools, and management consoles are high-value targets precisely because they are trusted and often have broad access. When those tools have vulnerabilities, the impact is amplified.

For businesses that outsource IT or backup management, the lesson is to understand what your provider runs on your behalf and how they respond to emerging threats. If you do not know whether your IT infrastructure includes an AhsayCBS server, this is a good time to find out.

If you are unsure where your business stands overall, our free quick security assessment takes about five minutes and covers 20 security areas, including backups.


This article is intended for general informational purposes only and does not constitute professional security, legal, or compliance advice. Details about the AhsayCBS vulnerabilities and observed exploitation are based on public reporting from Huntress, BleepingComputer, SecurityWeek, and vendor disclosures as of October 10, 2026. Information about affected versions and patching may evolve as the vendor and security researchers continue their investigation. Organizations should consult qualified cybersecurity professionals before acting on specific indicators of compromise or making operational changes based on this article.