Threat reportVulnerabilityTL-2026-3109
Threat Actors Exploit Critical AhsayCBS Flaws (CVE-2026-105133, CVE-2026-105134) to Drop Webshells and XMRig Cryptominer
Threat Actors Exploit Critical AhsayCBS Flaws (TL-2026-3109) is a critical-severity software vulnerability scored CVSS 10, first published 2026-10-09. It has no confirmed attribution, affects Ahsay AhsayCBS (Cloud Backup Server), references 2 CVEs (CVE-2026-105133, CVE-2026-105134), maps to 12 MITRE ATT&CK techniques (T1036.004, T1036.005, T1057), and is covered by 9 detection rules and 27 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 12MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 27Indicators of compromise
Key facts for TL-2026-3109
- Threat ID
- TL-2026-3109
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- managed-service-providers, backup-services, enterprise-it
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 27
- Updates
- 2026-10-09 · revalidated 1× · latest source
Malware and tooling in Threat Actors Exploit Critical AhsayCBS Flaws
Malware and tooling: JSP webshell, xmrig, NSSM, XMRig, certutil - S0160
How Threat Actors Exploit Critical AhsayCBS Flaws works
Huntress reports in-the-wild exploitation of AhsayCBS (Cloud Backup Server) chaining CVE-2026-105133 (improper authentication in checkSysPwd) with CVE-2026-105134 (unauthenticated OS command injection / RCE as NT AUTHORITY\SYSTEM via /rps/api/json/UpdateReceivers.do). Exploitation began 2026-10-07 23:20:15 UTC against at least five organizations, delivering JSP webshells and an XMRig Monero miner.
AhsayCBS is the central management server of the Ahsay backup platform. Two vulnerabilities published on 2026-10-04 were weaponized within days of disclosure. CVE-2026-105133 is an improper authentication flaw (CWE-287) in the checkSysPwd function (com/ahsay/obs/api/ApiStructsAction.java) of the API component, where manipulation of the 'random' argument lets an unauthenticated attacker substitute an arbitrary token for valid credentials. CVE-2026-105134 is an OS command injection (CWE-77/CWE-78) in the Replication Receiver component at /rps/api/json/UpdateReceivers.do, also reachable through manipulation of the 'random' argument, yielding unauthenticated command execution in the context of NT AUTHORITY\SYSTEM. CVE records rate CVE-2026-105134 at CVSS 3.1 10.0 and CVE-2026-105133 at CVSS 3.1 7.3 (Huntress labels them critical and medium respectively).
Huntress observed exploitation beginning 2026-10-07 at 23:20:15 UTC across at least five organizations as of 2026-10-08. Attackers chained the authentication bypass with the command injection to drop JSP webshells on the AhsayCBS host, then used the SYSTEM-level execution to download tooling from an Alibaba Cloud OSS bucket (imagefiles-backup.oss-ap-southeast-7.aliyuncs.com/javas/Office/win/), including certutil.exe-based retrieval of the vulnerable WinRing0x64.sys kernel driver used to boost mining performance.
Post-exploitation payloads: an XMRig Monero miner renamed edge.exe with config.json; a renamed NSSM (Non-Sucking Service Manager) binary named msedge.exe used to install a persistent Windows service named MicrosoftEdgeUpdateSvc that mimics the legitimate edgeupdate service; and Taskgmr.ps1, an apparently AI-assisted PowerShell script that monitors for Windows Task Manager, kills it (at 18:00 or if open more than an hour overnight), stops the mining service while Task Manager is open and restarts it on closure. Mining traffic goes to the pool xmr.kryptex.network port 8029 with worker identifier krxYMRN97D/creativejs. Huntress listed six IPs associated with the activity. No attribution to a named actor is made in the source; motivation is financial (cryptojacking), but webshell access allows secondary payloads, so Huntress recommends host re-imaging from trusted backups if compromise is found.
Version note: Huntress states AhsayCBS is affected 'through 10.3.4', whereas the CVE/VulDB records list 10.3.0-10.3.2 as vulnerable with 10.3.4 as the fixed release. These sources conflict; defenders should treat any version below the latest vendor release as exposed and verify against the Ahsay 10.3.4 release notes. Huntress published four Sigma rules covering unexpected child processes of cbssvcX64.exe/cbssvcX86.exe, edge-named binaries with daemonized flags or msedge_exe metadata, Task Manager-aware service control via PowerShell, and WinRing0 driver downloads via the command line.
MITRE ATT&CK techniques used in TL-2026-3109
Defense Evasion
T1036.004 Masquerade Task or Service; T1036.005 Match Legitimate Resource Name or Location
Discovery
Execution
T1059.001 PowerShell; T1569.002 System Services: Service Execution
Command and Control
Initial Access
T1190 Exploit Public-Facing Application
Impact
Persistence
T1505.003 Web Shell; T1543.003 Windows Service
Resource Development
Affected products and versions in Threat Actors Exploit Critical AhsayCBS Flaws
- Ahsay — AhsayCBS (Cloud Backup Server)
Vulnerable versions: 10.3.0; 10.3.1; 10.3.2; Huntress: through 10.3.4 (conflicting with CVE records)
Fixed in: 10.3.4 (per CVE/VulDB records)
Remediation for Threat Actors Exploit Critical AhsayCBS Flaws
Patches
- Upgrade AhsayCBS to 10.3.4 or later per CVE records and Ahsay release notes (https://www.ahsay.com/en/support/help-centre/release-notes/cbs/v10.3.4)
Immediate actions
- Restrict the AhsayCBS management interface to trusted IPs or require VPN access
- Hunt for JSP webshells in the AhsayCBS web directories and for child processes of cbssvcX64.exe/cbssvcX86.exe
- Block the listed IPs, the Alibaba OSS payload host and xmr.kryptex.network:8029 at the perimeter
- Search for the MicrosoftEdgeUpdateSvc service, edge.exe/msedge.exe outside Microsoft Edge paths, Taskgmr.ps1 and WinRing0x64.sys
- If IOCs are found, re-image the host from trusted backups because secondary backdoors are possible
Workarounds
- Block external access to /rps/api/json/UpdateReceivers.do and the API endpoints until patched
Longer-term hardening
- Do not expose backup management consoles to the internet
- Deploy the Huntress-published Sigma rules for post-exploitation activity
- Monitor for certutil.exe downloads and kernel driver loads such as WinRing0x64.sys
CVEs associated with Threat Actors Exploit Critical AhsayCBS Flaws
Weaknesses (CWE) in Threat Actors Exploit Critical AhsayCBS Flaws
Timeline of Threat Actors Exploit Critical AhsayCBS Flaws
- Ahsay releases AhsayCBS v10.3.4; release notes list no security fixes. Huntress and SecurityWeek later report this version is still vulnerable.
- CVE-2026-105133 and CVE-2026-105134 published; CVE records list AhsayCBS 10.3.0-10.3.2 as vulnerable and 10.3.4 as fixed.
- CVE records last modified; public exploit code reported available for both flaws.
- XMRig miner installed as service MicrosoftEdgeUpdateSvc via renamed NSSM and connected to xmr.kryptex.network:8029.
- Attackers retrieved Taskgmr.ps1, edge.exe, msedge.exe (NSSM), config.json and WinRing0x64.sys from an Alibaba Cloud OSS bucket (certutil used for the driver).
- JSP webshells dropped on compromised AhsayCBS hosts via UpdateReceivers.do, executing as NT AUTHORITY\SYSTEM.
- First in-the-wild exploitation observed by Huntress at 23:20:15 UTC, chaining the authentication bypass with unauthenticated command injection.
- Huntress published its analysis, confirming at least five affected organizations, IOCs, and four Sigma rules.
- SecurityWeek reports no patch is available, including for 10.3.4, and advises restricting the management interface.
Update history for TL-2026-3109
- 2026-10-09 — Unpatched AhsayCBS Vulnerabilities (CVE-2026-105133, CVE-2026-105134) Exploited in the Wild for Unauthenticated RCE: What changed No whitelisted field changes: severity (CRITICAL), exploitability (ACTIVE), status (ACTIVE), CVSS (10.0) and attribution are already at the reported values. Substantive change is patch status: the existing record lists 10.3.4 a
Sources cited for Threat Actors Exploit Critical AhsayCBS Flaws
- Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer (Huntress)
- CVE-2026-105134 (OpenCVE)
- CVE-2026-105133 (OpenCVE)
- CVE-2026-105134 (Rapid7 Vulnerability Database)
- CVE-2026-105134 (VulDB 413351)
- Ahsay AhsayCBS v10.3.4 Release Notes
- CVE-2026-105134 (INCIBE-CERT)
- CVE-2026-105133 (INCIBE-CERT)
Detection coverage for TL-2026-3109
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3109 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.