AhsayCBS backup utility active exploitation wave (CVE-2026-105133, CVE-2026-105134)
Exploitation Wave
Summary
Hide ▲
Show ▼
Active exploitation of CVE-2026-105133 and CVE-2026-105134 in AhsayCBS backup utility is enabling remote code execution and post-compromise deployment of web shells and XMRig miners. The wave began on 2026-10-07 and had reached five organizations by 2026-10-08. Externally accessible AhsayCBS management interfaces face immediate abuse risk until access is restricted.
Related Happenings
AhsayCBS backup utility actively exploited authentication bypass and command injection flaws (multiple vulnerabilities)
Vulnerability
H score49
First: 09.10.2026 15:47
Last: 09.10.2026 15:47
Sources 1
How related:
CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java" component.
CVE-2026-105134 (CVSS v4 score: 9.3) - An operating system command injection vulnerability in the Replication Receiver component.
About this happening:
CVE-2026-105133 and CVE-2026-105134 in AhsayCBS are being actively exploited, enabling attackers to bypass authentication and run arbitrary commands on exposed systems...
AhsayCBS backup utility actively exploited authentication bypass and command injection flaws (multiple vulnerabilities)
VulnerabilityHow related: CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java" component. CVE-2026-105134 (CVSS v4 score: 9.3) - An operating system command injection vulnerability in the Replication Receiver component.
About this happening: CVE-2026-105133 and CVE-2026-105134 in AhsayCBS are being actively exploited, enabling attackers to bypass authentication and run arbitrary commands on exposed systems...
AhsayCBS XMRig and web shell post-exploitation activity
Malware Activity
H score33
First: 09.10.2026 15:47
Last: 09.10.2026 15:47
Sources 1
How related:
"Post-exploitation, threat actors are conducting reconnaissance, dropping web shells, planting XMRig cryptominers masquerading as Microsoft Edge, and more," the cybersecurity company said.
About this happening:
Post-exploitation activity on compromised AhsayCBS hosts is dropping web shells and XMRig miners, extending attacker control and adding cryptomining after initial acce...
AhsayCBS XMRig and web shell post-exploitation activity
Malware ActivityHow related: "Post-exploitation, threat actors are conducting reconnaissance, dropping web shells, planting XMRig cryptominers masquerading as Microsoft Edge, and more," the cybersecurity company said.
About this happening: Post-exploitation activity on compromised AhsayCBS hosts is dropping web shells and XMRig miners, extending attacker control and adding cryptomining after initial acce...
Warlock SharePoint multi-sector ransomware campaign
Campaign
H score29
First: 02.10.2026 21:33
Last: 02.10.2026 21:33
Sources 1
About this happening:
The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university...
Warlock SharePoint multi-sector ransomware campaign
CampaignAbout this happening: The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university...
Arista mitigation guidance for Arista VeloCloud Orchestrator compensating controls for CVE-2026-93952
Advisory/Mitigation
H score53
First: 22.09.2026 15:29
Last: 22.09.2026 15:29
Sources 1
About this happening:
Arista issued temporary mitigation steps for exposed VeloCloud Orchestrator (VCO) deployments while a fixed release is pending, limiting the risk from actively exploited...
Arista mitigation guidance for Arista VeloCloud Orchestrator compensating controls for CVE-2026-93952
Advisory/MitigationAbout this happening: Arista issued temporary mitigation steps for exposed VeloCloud Orchestrator (VCO) deployments while a fixed release is pending, limiting the risk from actively exploited...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation Wave
H score53
First: 05.09.2026 10:31
Last: 05.09.2026 10:31
Sources 1
About this happening:
PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation WaveAbout this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
Timeline
-
09.10.2026 15:47 2 articles · 4h ago
AhsayCBS backup utility active exploitation wave (CVE-2026-105133, CVE-2026-105134)
Initial DisclosureChained exploitation of CVE-2026-105133 and CVE-2026-105134 in AhsayCBS began on 2026-10-07, when attackers started using the flaws to gain remote code execution on exposed hosts.
Show sources
- Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge — thehackernews.com — 09.10.2026 15:47
- Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge — thehackernews.com — 09.10.2026 15:47