TRENDING
Wooden two-dial chess clock with brass-rimmed white faces showing different times
October 10, 2026
A CNCF Post on NIS2 and DORA Turns Compliance Into a Backlog and Leaves the Classification Call Unowned
A hand holding an egg against a bright light in a dark room, with the light shining through the shell to show what is inside
October 10, 2026
Anthropic Launches OSS Scanner to Email Open-Source Maintainers AI Bug Reports No Human Has Reviewed
Two orange safety relief valves on grey pressure vessels in an industrial plant
October 10, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
October 10, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
A lugworm lying on wet sand and mud at low tide
October 10, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
10 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
A green classroom chalkboard wiped almost clean, with pale smears of chalk where earlier writing was erased
How to Prevent Lost Updates in a FastAPI API With ETag and If-Match
October 9, 2026
Back of an Exabyte Mammoth data cartridge, a tape cassette made for computer backups, shown on a white background
Ahsay Says Version 10.3.4 Fixes Two Exploited AhsayCBS Flaws, and Huntress Says It Does Not
October 9, 2026
An 1840 Mulready postal envelope with a red Leicester postmark dated 4 May 1840 and a handwritten address
How to Audit SPF, DKIM, and DMARC in Python to Stop Spoofed Email From Using Your Domain
October 9, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 233 Posts
News 236 Posts
Learning Hub 206 Posts
Home/News/Ahsay Says Version 10.3.4 Fixes Two Exploited AhsayCBS Flaws, and Huntress Says It Does Not
News

Ahsay Says Version 10.3.4 Fixes Two Exploited AhsayCBS Flaws, and Huntress Says It Does Not

Huntress says it first saw attacks on two AhsayCBS backup-server flaws on October 7 and that version 10.3.4 is also affected, while Ahsay says upgraded customers are protected.

October 9, 2026 5 Min Read
10

Security firm Huntress says it first saw attackers exploiting two flaws in AhsayCBS, the management console for Ahsay’s backup software, at 23:20 UTC on October 7. Huntress also says the current release, version 10.3.4, is affected. Ahsay’s own notice, dated October 9, says the opposite: partners “who have already upgraded to v10.3.4.0 are no longer affected by these vulnerabilities and are protected against remote exploitation by unauthenticated attackers.”

Table Of Content

  • What Huntress Saw
  • What the Attackers Did After Getting In
  • Two Statements About Version 10.3.4
  • What Neither Statement Settles
  • What Administrators Can Do Now
  • What to Watch

Neither side shows how it tested, and the public vulnerability records still match Ahsay’s account. Ahsay adds that upgrading does not resolve an earlier compromise, and Huntress advises re-imaging any host where its indicators turn up. I did not test AhsayCBS, so this compares public statements and records only.

What Huntress Saw

Huntress’s write-up, published October 8, says NVD disclosed the two CVEs on October 4 and that it began seeing exploitation at 23:20:15 UTC on October 7. That is about 88 hours after NVD published the records at 07:16 UTC on October 4. As of October 8, Huntress had seen five organizations targeted. It describes AhsayCBS as the console that “centralizes control of backup operations” and is “primarily used by managed service providers (MSPs) and system integrators.” Both NVD records say an exploit is public.

The write-up describes a two-step chain: “First, CVE-2026-105133 is used to bypass authentication. Then CVE-2026-105134 is used to gain code execution.” The second flaw gives unauthenticated remote code execution with SYSTEM privileges on the host, Huntress says.

CVE Where NVD says the flaw is Severity in the NVD record (scores supplied by VulDB) Role in the attacks Huntress describes
CVE-2026-105133 checkSysPwd function in com/ahsay/obs/api/ApiStructsAction.java (API component) 5.5 Medium (CVSS 4.0), 7.3 High (CVSS 3.1) Authentication bypass, first step
CVE-2026-105134 /rps/api/json/UpdateReceivers.do (Replication Receiver component) 9.3 Critical (CVSS 4.0), 10.0 Critical (CVSS 3.1) Command injection leading to code execution with SYSTEM privileges, second step

What the Attackers Did After Getting In

Huntress saw two patterns. In some incidents the actors dropped JSP webshells into the web application directory immediately. In others, the AhsayCBS service process cbssvcX64.exe ran commands that fetched Taskgmr.ps1, msedge.exe, edge.exe and config.json into a Temp folder from imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com, a payload host on Alibaba Cloud Object Storage. The file edge.exe is the XMRig Monero miner under a Microsoft Edge name, and msedge.exe is a modified copy of the legitimate NSSM service utility. A Windows service called MicrosoftEdgeUpdateSvc, styled to look like the real Edge Update service, ran msedge.exe with SYSTEM privileges. Huntress says the actors likely used NSSM to keep the miner running after crashes or reboots, and the miner connected to a pool on port 8029.

One script, Taskgmr.ps1, “appears to be an AI-assisted script (given the commented code),” Huntress says. It stops the miner’s service while Task Manager is open and restarts it when Task Manager closes. In one incident the actors also downloaded WinRing0x64.sys, a legitimate but vulnerable kernel driver, which Huntress says gave the miner kernel-level access to the hardware. The write-up reports reconnaissance, webshells and the miner. It does not describe ransomware or data theft.

Two Statements About Version 10.3.4

The CVE records came from VulDB. Both say AhsayCBS “up to 10.3.2” is affected, and they say upgrading to 10.3.4 “is able to mitigate this issue” (CVE-2026-105133) or “is able to resolve this issue” (CVE-2026-105134). Both cite Ahsay’s 10.3.4 release notes as a reference. That release shipped about two months before the CVEs were published: Ahsay’s announcement is dated August 4 and the release-notes page is headed August 5. The announcement lists Hyper-V backup on Windows 10 and 11, macOS 26.6 and Debian 12.15 and 13.6 support. The release notes describe themselves as listing “the major features,” with enhancements such as Debian support and bug fixes for backup, restore and client-connection problems. Neither page mentions a security fix, although Ahsay’s January announcement for 10.1.6 did list an “AhsayCBS XSS vulnerability fix.”

Huntress’s write-up carries an update dated 6 pm ET on October 8. It says that after further investigation it “has determined that Ahsay 10.3.4 is also affected by these vulnerabilities,” and that “previous reporting indicated that 10.3.4 was not susceptible.” Huntress says it contacted Ahsay and shared its research, and that “until a patch is available” administrators should restrict access to the management interface. SecurityWeek, reporting on October 9, relays the same finding: “the latest AhsayCBS version, 10.3.4, is also affected.”

Ahsay’s clarification, dated October 9, does not name Huntress. It says Ahsay has “received inquiries from various sources” about the two vulnerabilities, “both of which were addressed in AhsayCBS v10.3.4.0, released on 4 August 2026,” and that upgraded partners “are no longer affected by these vulnerabilities and are protected against remote exploitation by unauthenticated attackers.” If a server “was compromised prior to upgrading to v10.3.4.0, the upgrade itself would not resolve any issues arising from the compromise,” the notice adds, and it recommends engaging “qualified cybersecurity professionals” to investigate. Ahsay writes the version as 10.3.4.0 while Huntress and NVD write 10.3.4, but its release announcement for 10.3.4 carries the same August 4 date, so I treat them as one release.

What Neither Statement Settles

  • Huntress does not publish its evidence for the 10.3.4 finding, and the write-up does not say which versions the five targeted organizations were running.
  • Ahsay does not say how it verified the fix or which change addressed the flaws, and its release notes name none.
  • NVD’s records, whose status is “Deferred,” were last modified on October 6 and still say “up to 10.3.2” (checked at 19:15 UTC on October 9).
  • CISA’s Known Exploited Vulnerabilities catalog did not list either CVE in its October 8 update (catalog version 2026.10.08).

What Administrators Can Do Now

  • Limit the management interface. Huntress says the exploit “targets the externally accessible web app service on the host” and recommends access “limited to trusted IP addresses only or require VPN.” That costs nothing if Ahsay is right and matters if Huntress is.
  • Look for Huntress’s indicators: processes spawned by cbssvcX64.exe or cbssvcX86.exe outside the service’s normal startup and maintenance commands (the basis of one of Huntress’s four published Sigma rules), a service named MicrosoftEdgeUpdateSvc, Taskgmr.ps1, msedge.exe, edge.exe and config.json in Temp folders, unexpected .jsp files in the web application directory, and connections to the payload host or to port 8029.
  • If any indicator turns up, Huntress says to re-image the host from a trusted backup, because attackers “have been able to hide secondary backdoors for extended persistence.” Ahsay likewise says an upgrade alone will not clean up an earlier compromise.
  • Until the two accounts are reconciled, a version check that shows 10.3.4 settles little. That is my reading, and the restrictions above are cheap enough to apply either way.

What to Watch

Three things would settle the dispute: Huntress publishing its test evidence or a version breakdown, Ahsay naming the change that fixed the flaws or shipping a newer build (its release-notes index lists 10.3.4 as the newest AhsayCBS 10 release), and NVD revising the affected range. Until then, administrators have two vendor statements and no tiebreaker. The payload so far has been cryptomining, but the access it came through, code execution with SYSTEM privileges on the server that runs the backup console, would allow more. That last point is my reading, not something Huntress reports. For a similar case of an exploited flaw with no patch, see our coverage of the unpatched FortiMail flaw.

Tags:

AhsayAuthentication BypassHuntressMSP SecurityRemote Code ExecutionVulnerability Management

Share

An 1840 Mulready postal envelope with a red Leicester postmark dated 4 May 1840 and a handwritten address
Previous Post

How to Audit SPF, DKIM, and DMARC in Python to Stop Spoofed Email From Using Your Domain

A green classroom chalkboard wiped almost clean, with pale smears of chalk where earlier writing was erased
Next Post

How to Prevent Lost Updates in a FastAPI API With ETag and If-Match

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
09 Oct
How to Prevent Lost Updates in a FastAPI API With ETag and If-Match
09 Oct
Ahsay Says Version 10.3.4 Fixes Two Exploited AhsayCBS Flaws, and Huntress Says It Does Not
Trending
October 9, 2026
How to Prevent Lost Updates in a FastAPI API With ETag and If-Match
October 9, 2026
Ahsay Says Version 10.3.4 Fixes Two Exploited AhsayCBS Flaws, and Huntress Says It Does Not
October 9, 2026
How to Audit SPF, DKIM, and DMARC in Python to Stop Spoofed Email From Using Your Domain
October 9, 2026
A CNCF Post on NIS2 and DORA Turns Compliance Into a Backlog and Leaves the Classification Call Unowned
October 9, 2026
Anthropic Launches OSS Scanner to Email Open-Source Maintainers AI Bug Reports No Human Has Reviewed
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026