AhsayCBS Zero-Day Chain: Backup Servers Under Active Attack
Answer first: Internet-exposed AhsayCBS backup servers are being compromised through an authentication-bypass and command-injection chain. Versions through 10.3.4 should be treated as vulnerable, and no verified fixed release was available when this briefing was published. Restrict access immediately and investigate before assuming an upgrade solved the problem.
DataWater Threat Intelligence Desk | October 10, 2026 | Updated with public information available at publication
Threat level: Critical — active exploitation confirmed by Huntress
Affected: AhsayCBS backup-management servers through version 10.3.4, according to Huntress testing.
Attack chain: CVE-2026-105133 authentication bypass followed by CVE-2026-105134 OS command injection.
Observed impact: SYSTEM-level code execution, JSP webshells, reconnaissance and XMRig cryptominers disguised as Microsoft Edge.
Immediate action: Remove the management interface from public access, preserve evidence and hunt for compromise. Do not rely on 10.3.4 as a fix.
What happened
On October 9, Huntress disclosed that it had observed attackers exploiting two recently published AhsayCBS vulnerabilities. Exploitation began in its telemetry on October 7 at 23:20 UTC. By October 8, the company had identified activity affecting five organizations.
AhsayCBS is the central management server for Ahsay backup environments. Managed service providers and system integrators use it to manage users, storage and backup policies. That makes this more consequential than an ordinary cryptomining incident: a compromised backup control plane can expose administrative credentials, customer environments and the systems an organization expects to rely on during recovery.
The attackers chained two flaws:
- CVE-2026-105133: improper authentication in the
checkSysPwdfunction. Huntress says attackers can substitute a random value where valid authentication should be required. - CVE-2026-105134: OS command injection in the Replication Receiver endpoint
/rps/api/json/UpdateReceivers.do. In the observed chain, it delivered unauthenticated remote code execution asNT AUTHORITY\SYSTEM.
Huntress initially tested the CVE records’ remediation claim that version 10.3.4 resolved the vulnerabilities. It later updated its report after determining that 10.3.4 was also affected. This discrepancy matters: NVD and the CVE record still described versions through 10.3.2 as affected and presented 10.3.4 as the upgrade target when this article was written.
Affected versions and remediation status
| Product | Status | What defenders should do |
|---|---|---|
| AhsayCBS 10.3.2 and earlier | Affected in CVE records and exploitation research | Restrict exposure and investigate immediately |
| AhsayCBS 10.3.4 | Huntress confirmed it remains vulnerable | Do not treat this release as remediation |
| Later release | No verified fixed build identified at publication | Monitor Ahsay guidance and validate any future fix independently |
There is no CISA Known Exploited Vulnerabilities deadline yet. That distinction matters: Huntress has confirmed exploitation, but CISA had not added either CVE to KEV when this briefing was prepared. The absence of a federal deadline is not evidence of low risk and should not delay private-sector action.
What attackers did after access
Huntress observed cbssvcX64.exe, the AhsayCBS service process, spawning suspicious commands. In some incidents, attackers placed JSP webshells in the application directory. In others, they downloaded files from an Alibaba Cloud Object Storage address into temporary directories.
The observed files included Taskgmr.ps1, msedge.exe, edge.exe and config.json. The executables were associated with XMRig cryptocurrency mining while masquerading as Microsoft Edge components. Researchers also described a PowerShell script that monitored Windows Task Manager and attempted to close it when it remained open during overnight hours. Huntress assessed that script as appearing AI-assisted, but that assessment does not establish who created it or prove that generative AI was used in the intrusion.
Cryptomining may be the visible payload, not the full business impact. A persistent webshell on a backup server provides an attacker with a durable foothold and an opportunity to inspect credentials, configurations and connected systems.
Why CISOs should treat this as a backup-resilience incident
The backup platform may be both the entry point and a recovery dependency. Incident-response plans often assume backup infrastructure remains trustworthy after compromise elsewhere. Here, defenders must verify that assumption before restoring systems or rotating into disaster-recovery procedures.
MSP concentration increases downstream risk. A single AhsayCBS server may administer backup services for multiple customers. This is the same concentration problem covered in DataWater’s enterprise third-party and supply-chain risk guide: one privileged provider platform can multiply the blast radius.
Published remediation data is conflicting. The CVE records recommend 10.3.4, while exploitation research says that version is vulnerable. Security teams should verify outcomes rather than closing tickets based only on a version string. That lesson also appears in DataWater’s analysis of how attackers compress the time from initial access to impact.
Priority defensive actions
Do now
- Identify every AhsayCBS server, including MSP-hosted, disaster-recovery, lab and legacy instances. Record version, public IP, owner and customers or business units served.
- Block public access to the management and replication interfaces. Allow only trusted administration networks, VPN sources or an authenticated access proxy. If business operations permit, disconnect the server until a verified fix is available.
- Preserve evidence before cleanup. Collect AhsayCBS, web-server, Windows event, EDR, firewall and proxy logs. Capture volatile evidence where your incident-response process supports it.
- Hunt for suspicious children of
cbssvcX64.exe, JSP files created in the application directory, and the observed filenamesTaskgmr.ps1,msedge.exe,edge.exeandconfig.jsonin temporary paths.
Within 24 hours
- Check for outbound retrieval from the reported Alibaba Cloud Object Storage host and investigate unexpected PowerShell, command-shell or Java activity.
- Review all administrator and service accounts used by AhsayCBS. Rotate credentials and secrets only after containment so active attackers cannot immediately capture replacements.
- Validate backup integrity from a separate trust domain. Confirm immutable or offline copies exist and test restoration without depending on the suspected server.
- Scope every managed customer or tenant if the server belongs to an MSP. Do not assume that finding a miner rules out credential theft or lateral movement.
Before returning the platform to service
Rebuild compromised systems from known-good media rather than merely deleting the miner. Apply a vendor-verified fixed release when one is available, keep the management plane private, restore only validated configuration data and monitor the rebuilt host for unexpected child processes and outbound connections.
Executive decision: If your organization or MSP operates AhsayCBS 10.3.4 or earlier, treat it as an incident-response question—not only a patch-management ticket. Ask whether the server was publicly reachable and whether logs prove it was not compromised.
Executive takeaway
Active exploitation is confirmed, the commonly cited fixed version is still vulnerable, and the target controls backups. That combination justifies emergency action even without a CISA KEV entry.
Restrict access first. Preserve evidence second. Hunt and validate backup integrity before trusting the environment again. A clean-looking dashboard or an installed 10.3.4 build is not enough.
Sources
Primary and direct technical sources: Huntress active-exploitation analysis, published October 9, 2026; CVE-2026-105133 record; CVE-2026-105134 record; and NVD CVE-2026-105134. Facts reflect public information available October 10, 2026.
