BREACH WATCH BRIEF High ☁️ Breach

Unpatched AhsayCBS Backup Platform Vulnerabilities Exploited to Deploy Webshells and Crypto Miners

Threat actors chained two unpatched AhsayCBS flaws (CVE‑2026‑105133 and CVE‑2026‑105134) to install web‑shells and XMRig miners on at least five MSP‑hosted environments. The incident underscores the importance of continuous vulnerability management and auditable patch‑deployment evidence for compliance readiness.

SeverityHigh
Type☁️ Breach
ConfidenceHigh
ReportedOct 9, 2026
Technology & SaaS Managed Service Providers System integrators using AhsayCBS for backup Vulnerability Exploit Other

What happened

Attackers used CVE‑2026‑105133 to bypass authentication and CVE‑2026‑105134 for OS command injection, then deployed JSP web‑shells and a PowerShell‑driven XMRig miner on systems managed by AhsayCBS. The miner persisted via a forged MicrosoftEdgeUpdateSvc service and employed an AI‑assisted script to hide its activity.

Why it matters for trust and compliance

  • The breach illustrates why a control‑assurance program must continuously monitor for unpatched vulnerabilities, capture remediation evidence, and maintain a defensible audit trail of patch‑management actions.
  • Enables continuous mapping of vulnerability‑remediation controls to multiple frameworks.
  • Provides auditable evidence that patching and access restrictions are enforced and verified.

Who is affected

Managed Service Providers System integrators using AhsayCBS for backup

Recommended actions

  1. Upgrade AhsayCBS to version 10.3.2 or later (or apply vendor‑provided patches).
  2. Restrict management‑interface access to trusted IP addresses only.
  3. Deploy the Huntress IoCs and Sigma rules to detect lingering compromise.
  4. Document remediation steps in your control‑evidence repository for audit readiness.

Get the Breach Digest

The incidents that matter for your vendors and your data, analysed for practitioners, in one email.