CVE-2026-105134
CVSS 10 CRITICAL: a flaw has been found in Ahsay AhsayCBS up to 10.3.2. EPSS 2% (78th percentile).
Vulnerabilities · 6h ago
BleepingComputer reported active exploitation of two unpatched AhsayCBS flaws, CVE-2026-105133 and CVE-2026-105134, against backup servers running versions up to 10.3.2. The attacks are being used to drop webshells and install cryptocurrency miners.
The webshell gives attackers a small remote command box on the server, so they can come back through the management interface instead of needing the original bug again. On a backup platform, that means the compromise can sit in the management plane itself, with reach into backup data and the systems the server administers.
That makes this more than a one-off nuisance on an internet-facing app. If AhsayCBS is exposed in your environment, the durable exposure is the backup manager as a beachhead, and cleanup has to assume the attacker may already have used it to extend access.
CVSS 10 CRITICAL: a flaw has been found in Ahsay AhsayCBS up to 10.3.2. EPSS 2% (78th percentile).
CVSS 7.3 HIGH: a vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. EPSS 0.4% (30th percentile).
1 source covering this story
Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners.
Part of the PlainSec briefing for 2026-10-09