Threat Intelligence, Vulnerability Management

Critical vulnerabilities in AhsayCBS exploited for webshells and crypto miners

Internet Code Hack Background

Threat actors are actively exploiting two vulnerabilities, one critical and one medium-severity, in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. These vulnerabilities, still unpatched in some versions, are being used to gain unauthorized access to systems typically managed by managed service providers and system integrators, with further coverage provided by Bleeping Computer.

The attacks chain two vulnerabilities: CVE-2026-105133, an authentication bypass with a public exploit, and CVE-2026-105134, which allows for OS command injection. Although reported as fixed in AhsayCBS 10.3.2, researchers found they also affect the latest version, 10.3.4. After bypassing authentication, attackers deploy Java Server Page (JSP) webshells and the XMRig cryptocurrency miner, disguised as edge.exe. Persistence is achieved through a service named ‘MicrosoftEdgeUpdateSvc’ running a modified copy of the Non-Sucking Service Manager (NSSM) utility. An AI-assisted PowerShell script, Taskgmr.ps1, conceals mining activity by stopping the service when Task Manager is opened and restarting it when closed. The script also terminates Task Manager at 6 p.m. or if left open overnight. In some cases, the WinRing0x64.sys driver was deployed to unlock more hardware resources for the miner. Until a patch is available, administrators are advised to restrict access to the AhsayCBS management interface to trusted IP addresses and investigate signs of compromise.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds