Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Elon’s CRAZY plan for SpaceX to Dwarf the World Economy. Breaking it down – NextBigFuture.com

    October 9, 2026

    HMD Pulse 2T Pro specs and images leak showing a dot matrix rear display

    October 9, 2026

    Want an iPhone Duo? These AT&T deals will knock the price down

    October 9, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
    Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
    Cybersecurity

    Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

    The Tech GuyBy The Tech GuyOctober 9, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Hackers have been exploiting two unpatched vulnerabilities in the AhsayCBS backup solution for remote code execution (RCE), cybersecurity firm Huntress warns.

    Advertisement

    A centralized cloud backup server management console developed by Ahsay Systems, AhsayCBS provides backup policy, storage, and user management and is popular among MSPs and system integrators.

    Tracked as CVE-2026-105133 and CVE-2026-105134, the exploited security defects allow attackers to manipulate arguments in certain functions of the tool to bypass authentication and inject OS commands.

    They were disclosed on October 4, when NIST warned that exploit code targeting them had been released, and that all AhsayCBS versions up to 10.3.2 were affected.

    On Thursday, Huntress warned that attackers have exploited the two flaws in the wild and that the latest AhsayCBS version, 10.3.4, is also affected.

    “Until a patch is available, we recommend restricting access to the management interface and investigating for signs of compromise,” Huntress says.

    Advertisement. Scroll to continue reading.

    According to Huntress, threat actors are chaining the two bugs to access vulnerable systems and execute arbitrary code on them. As of October 8, at least five organizations had been targeted.

    “Huntress observed threat actors exploiting the vulnerabilities to gain unauthenticated remote code execution and deploy webshells on exposed systems,” the cybersecurity firm notes.

    It also warns that CVE-2026-105134 can be exploited for unauthenticated RCE with System privileges through an API of the Replication Receiver component.

    “The API contains an authentication bypass that could allow for a random token to substitute valid credentials. After exploitation, a threat actor configured a malicious receiver and dropped a Java Server Page (JSP) webshell into the application directory served by the CBS application,” Huntress explains.

    After gaining initial access, the attackers conducted reconnaissance and deployed XMRig cryptominers disguised as Microsoft Edge. They also planted an AI-assisted PowerShell script to monitor Task Manager and terminate it if it remains open for too long.

    They also achieved persistence by creating a Windows service masquerading as Microsoft Edge Update to execute a modified copy of the legitimate NSSM utility named msedge.exe with System privileges.

    “NSSM can support other programs to ensure they stay running and restart after a crash or reboot, and threat actors in this incident likely used it to maintain persistence for edge.exe, while disguising the service-related binary as a legitimate-looking file,” Huntress notes.

    In one attack, the hackers deployed WinRing0x64.sys, a legitimate but vulnerable kernel driver that enabled the cryptocurrency miner to operate with kernel-level access.

    “Organizations should restrict AhsayCBS management interface web access, as the exploit targets the externally accessible web app service on the host. Access should be limited to trusted IP addresses only or require VPN,” Huntress recommends.

    Related: Citrix Urges Immediate Patching of Critical NetScaler Vulnerability

    Related: Google Pixel 10 Exploits Earned Hackers $560,000 at Pwn2Own

    Related: Cisco Patches a Dozen Critical Vulnerabilities

    Related: Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    In Other News: AI Used in Korean Bank Breaches, Poem-Guided Botnet, Empire Admin Gets 40 Years

    October 9, 2026

    Formula Predicts When AI Chatbots Are at Risk of Turning Bad

    October 9, 2026

    Security Awareness Training Isn’t Dead, but It Needs a Rethink

    October 8, 2026

    Cisco Patches a Dozen Critical Vulnerabilities

    October 8, 2026

    Rein Security Raises $25 Million to Guard AI Agents at Runtime

    October 8, 2026

    Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform

    October 8, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026393 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Elon’s CRAZY plan for SpaceX to Dwarf the World Economy. Breaking it down – NextBigFuture.com

    October 9, 2026

    HMD Pulse 2T Pro specs and images leak showing a dot matrix rear display

    October 9, 2026

    Want an iPhone Duo? These AT&T deals will knock the price down

    October 9, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.