Back to Newsroom
Threat Intel

AhsayCBS Flaws Chained to Deploy Web Shells and XMRig Miners Disguised as Edge

Attackers are chaining two AhsayCBS vulnerabilities to run code on exposed backup servers. The 10.3.4 fix reportedly falls short, so restricting access to the management interface is the main defence for now.

AhsayCBS Flaws Chained to Deploy Web Shells and XMRig Miners Disguised as Edge

AhsayCBS Flaws Chained to Plant Web Shells and Disguised Crypto Miners

Attackers are chaining two newly disclosed vulnerabilities in AhsayCBS, a widely used backup server, to take over exposed installations. According to research by Huntress, they then drop web shells and an XMRig cryptocurrency miner that poses as Microsoft Edge.

What happened

Two flaws are involved:

  • CVE-2026-105133 (CVSS v4 5.5) is an improper authentication weakness in the checkSysPwd() function (com/ahsay/obs/api/ApiStructsAction.java).
  • CVE-2026-105134 (CVSS v4 9.3) is an OS command injection in the Replication Receiver component.

Neither bug is catastrophic alone. Together they let a remote, unauthenticated attacker get past the login and run arbitrary commands on the server. Huntress says exploitation began late on 7 October 2026 (UTC). By 8 October, five organisations had been targeted, and one more incident has since been reported. So far there is no sign of mass exploitation.

After gaining access, the attackers:

  • run reconnaissance and plant web shells for persistent access;
  • deploy XMRig named edge.exe so it blends in with normal browser processes;
  • add a PowerShell script (Taskgmr.ps1), which researchers believe was written with AI help. It stops the miner when Task Manager opens and closes Task Manager if it stays open overnight;
  • in at least one case, use the built-in certutil.exe to fetch WinRing0x64.sys, a legitimate but vulnerable driver, to get kernel-level hardware access and boost mining output.

Why it matters

The most important detail is about the patch. NVD lists the issues as fixed in AhsayCBS 10.3.4, but Huntress reports that 10.3.4 is also affected. Upgrading should therefore not be treated as a complete fix. Until the vendor confirms a working patch, these flaws effectively behave like zero-days.

Backup servers hold copies of an organisation's most sensitive data and usually have broad network access. That makes them valuable footholds. A miner is the visible payload today, but the same access could deliver ransomware or data theft.

What to do

  1. Take the AhsayCBS management interface off the internet. Allow access only from trusted IP addresses or over a VPN. This is the main mitigation available right now.
  2. Inventory your exposure. Check whether any AhsayCBS instance, including one run by an MSP on your behalf, can be reached from the internet.
  3. Hunt for compromise. Look for unexpected edge.exe processes outside the normal Edge install path, Taskgmr.ps1, WinRing0x64.sys in TEMP folders, certutil.exe downloads, new or unknown files in the web root, and sustained unexplained CPU load.
  4. Assume persistence if you find anything. Removing the miner does not remove the web shells. Rebuild or fully clean the host and rotate any credentials stored on it.
  5. Watch for a vendor fix and apply it once it is confirmed to cover both CVEs. Do not rely on 10.3.4 alone.

Based on research published by Huntress and reported by The Hacker News.

SHARE