AhsayCBS backup utility actively exploited authentication bypass and command injection flaws (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-105133 and CVE-2026-105134 in AhsayCBS are being actively exploited, enabling attackers to bypass authentication and run arbitrary commands on exposed systems. The chained flaws affect the checkSysPwd() authentication path and the Replication Receiver component, turning a backup utility weakness into remote code execution risk. Exploitation began on October 7, 2026 and quickly expanded to multiple organizations, with post-exploitation activity including web shells and XMRig miners.
Related Happenings
AhsayCBS backup utility active exploitation wave (CVE-2026-105133, CVE-2026-105134)
Exploitation Wave
H score51
First: 09.10.2026 15:47
Last: 09.10.2026 15:47
Sources 1
How related:
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners.
About this happening:
Active exploitation of CVE-2026-105133 and CVE-2026-105134 in AhsayCBS backup utility is enabling remote code execution and post-compromise deployment of web she...
AhsayCBS backup utility active exploitation wave (CVE-2026-105133, CVE-2026-105134)
Exploitation WaveHow related: Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners.
About this happening: Active exploitation of CVE-2026-105133 and CVE-2026-105134 in AhsayCBS backup utility is enabling remote code execution and post-compromise deployment of web she...
AhsayCBS XMRig and web shell post-exploitation activity
Malware Activity
H score33
First: 09.10.2026 15:47
Last: 09.10.2026 15:47
Sources 1
How related:
"Post-exploitation, threat actors are conducting reconnaissance, dropping web shells, planting XMRig cryptominers masquerading as Microsoft Edge, and more," the cybersecurity company said.
About this happening:
Post-exploitation activity on compromised AhsayCBS hosts is dropping web shells and XMRig miners, extending attacker control and adding cryptomining after initial acce...
AhsayCBS XMRig and web shell post-exploitation activity
Malware ActivityHow related: "Post-exploitation, threat actors are conducting reconnaissance, dropping web shells, planting XMRig cryptominers masquerading as Microsoft Edge, and more," the cybersecurity company said.
About this happening: Post-exploitation activity on compromised AhsayCBS hosts is dropping web shells and XMRig miners, extending attacker control and adding cryptomining after initial acce...
Warlock SharePoint multi-sector ransomware campaign
Campaign
H score29
First: 02.10.2026 21:33
Last: 02.10.2026 21:33
Sources 1
About this happening:
The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university...
Warlock SharePoint multi-sector ransomware campaign
CampaignAbout this happening: The Warlock ransomware campaign is using SharePoint vulnerabilities to break into a water utility, telecom provider, regional government body, and university...
Phantom Mantis shifts The Gentlemen into an independent ransomware partnership program
Threat Actor Meta
H score24
First: 11.06.2026 19:50
Last: 11.06.2026 19:50
Sources 1
About this happening:
Phantom Mantis moved The Gentlemen from dependence on other ransomware ecosystems into an independent partnership program, expanding its operational autonomy and affil...
Phantom Mantis shifts The Gentlemen into an independent ransomware partnership program
Threat Actor MetaAbout this happening: Phantom Mantis moved The Gentlemen from dependence on other ransomware ecosystems into an independent partnership program, expanding its operational autonomy and affil...
Everest Forms Pro CVE-2026-3300 active exploitation wave
Exploitation Wave
H score87
First: 05.06.2026 11:38
Last: 05.06.2026 11:38
Sources 1
About this happening:
Active exploitation of CVE-2026-3300 in Everest Forms Pro is driving complete site compromise risk for WordPress sites. Attackers have been using the flaw for arbitrar...
Everest Forms Pro CVE-2026-3300 active exploitation wave
Exploitation WaveAbout this happening: Active exploitation of CVE-2026-3300 in Everest Forms Pro is driving complete site compromise risk for WordPress sites. Attackers have been using the flaw for arbitrar...
Timeline
-
09.10.2026 15:47 2 articles · 4h ago
AhsayCBS backup utility actively exploited authentication bypass and command injection flaws (multiple vulnerabilities)
Initial DisclosureThe flaws were assigned CVE-2026-105133 and CVE-2026-105134 on October 4, 2026, establishing a chained weakness in AhsayCBS that could bypass authentication and enable command execution. Early guidance described the latest software release, 10.3.4, as addressing the issues.
Show sources
- Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge — thehackernews.com — 09.10.2026 15:47
- Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge — thehackernews.com — 09.10.2026 15:47