www.securityweek.com 9 Oct 2026, 10:23 UTC

Hackers Exploit AhsayCBS Flaws to Deploy Webshells and Crypto Miners

Hackers Exploit AhsayCBS Flaws to Deploy Webshells and Crypto Miners
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

SECURITYWEEK reports that two unpatched flaws in AhsayCBS, CVE-2026-105133 and CVE-2026-105134, are being exploited in the wild to achieve unauthenticated remote code execution. The defects allow an attacker to manipulate arguments in certain functions to bypass authentication and inject OS commands, with NIST noting exploit code released and all versions up to 10.3.2 affected; Huntress later added that version 10.3.4 remains vulnerable as well.

Huntress observed threat actors chaining the two bugs to gain unauthenticated RCE, deploy webshells, and use exposed AhsayCBS instances to their advantage. One vulnerability, CVE-2026-105134, can be exploited via the Replication Receiver API to bypass authentication and run code with System privileges, including dropping a JSP webshell into the CBS application directory. By October 8, at least five organisations had been targeted.

Post-initial access, attackers conducted reconnaissance, deployed XMRig cryptocurrency miners disguised as Microsoft Edge, and inserted an AI-assisted PowerShell script to monitor Task Manager and terminate it if necessary.

Further persistence and privilege escalation are described: attackers established a Windows service masquerading as Microsoft Edge Update to run a modified NSSM binary (msedge[.]exe) with System rights, and in one instance deployed the legitimate but vulnerable kernel driver WinRing0x64[.]sys to grant kernel-level access to the miner. Security guidance from Huntress urges restricting AhsayCBS management interface web access to trusted IPs or VPN, as the exploit targets the externally facing web app service.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline