Unpatched AhsayCBS Flaws Exploited to Deploy Webshells, Mine Crypto
Threat actors are exploiting unpatched vulnerabilities in AhsayCBS to deploy webshells and cryptocurrency miners.
Intelligence analysis by Qwen 2.5 (3B)

Security researchers warn of attacks targeting AhsayCBS backup management platform, which has unpatched vulnerabilities exploited to deploy malicious webshells and cryptocurrency miners.
Bad guys found two holes in a backup software and used them to put a fake website and a coin-stealing program on computers.
Analysis
{"heading_1":"Background on AhsayCBS","content_1":"AhsayCBS is a backup management platform used by managed service providers (MSPs) and system integrators. The platform is currently affected by two unpatched vulnerabilities, CVE-2026-105133 and CVE-2026-105134.","heading_2":"Vulnerability Details","content_2":"CVE-2026-105133 is an authentication bypass vulnerability, while CVE-2026-105134 allows for OS command injection. Both vulnerabilities are reported as fixed in AhsayCBS 10.3.2, but Huntress found that they also affect Ahsay 10.3.4, the latest version.","heading_3":"Attack Methodology","content_3":"Threat actors chained the two vulnerabilities to bypass authentication and execute code. They deployed Java Server Page (JSP) webshells and a cryptocurrency miner disguised as edge.exe. The miner persists on the host via a modified copy of the legitimate Non-Sucking Service Manager (NSSM) utility and a PowerShell script that stops and restarts the service at specific times."}
Key points
- AhsayCBS backup management platform is affected by unpatched vulnerabilities
- Threat actors used two vulnerabilities to deploy webshells and cryptocurrency miners
- AhsayCBS 10.3.2 is reported as fixed, but Huntress found the vulnerabilities also affect Ahsay 10.3.4
With better security practices, such attacks can be prevented in the future.
If the software is not updated, the bad guys might find more holes and use them to do more damage.


