SECURITY researchers warn of active, wild exploitation of two AhsayCBS vulnerabilities that together enable remote code execution on affected hosts. The attackers chain an authentication weakness (CVE-2026-105133) in ApiStructsAction[.]java with a remote code execution flaw (CVE-2026-105134) in the Replication Receiver, using a malicious UpdateReceivers[.]do configuration to plant a webshell and gain SYSTEM-level access.
Once inside, they deploy a Monero cryptocurrency miner and a persistence mechanism, including a modified NSSM utility, and use a PowerShell script (Taskgmr.ps1) to conceal activity by terminating the miner when Task Manager is opened and restarting it afterwards. The operation also leverages the WinRing0x64[.]sys kernel driver to gain hardware access. Huntress notes that these two flaws are being chained in active campaigns, and VirusTotal results cited in reporting are shown to corroborate the activity.
Affected software and evidence indicate that all AhsayCBS versions up to and including 10.3.4 are vulnerable. As of 7 October, exploitation was observed in the wild against exposed enterprise systems, with five organisations reportedly targeted by 8 October. The combined effect is potential complete host compromise, including the loss of backup server credentials and the risk of disrupted recovery processes across client networks.
Immediate actions recommended by researchers include isolating exposed management consoles and applying mitigations. Although no official vendor patch is stated as released, the guidance urges updating to 10.3.4 and tightening access controls: restrict public internet access to the AhsayCBS management interface, allow connections only from trusted administrative IPs, and monitor for unusual cbssvcX64[.]exe processes. Re-imaging from trusted backups and deploying detection rules (e.g., Huntress Sigma) are advised if indicators of compromise are found.