# Threat Actors Exploit Critical AhsayCBS Flaws (CVE-2026-105133, CVE-2026-105134) to Drop Webshells and XMRig Cryptominer

> Huntress reports in-the-wild exploitation of AhsayCBS (Cloud Backup Server) chaining CVE-2026-105133 (improper authentication in checkSysPwd) with CVE-2026-105134 (unauthenticated OS command injection / RCE as NT AUTHORITY\SYSTEM via /rps/api/json/UpdateReceivers.do). Exploitation began 2026-10-07 23:20:15 UTC against at least five organizations, delivering JSP webshells and an XMRig Monero miner.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T10:31:56.109Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3109
- **ID:** TL-2026-3109
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-105133, CVE-2026-105134

## Description

AhsayCBS is the central management server of the Ahsay backup platform. Two vulnerabilities published on 2026-10-04 were weaponized within days of disclosure. CVE-2026-105133 is an improper authentication flaw (CWE-287) in the checkSysPwd function (com/ahsay/obs/api/ApiStructsAction.java) of the API component, where manipulation of the 'random' argument lets an unauthenticated attacker substitute an arbitrary token for valid credentials. CVE-2026-105134 is an OS command injection (CWE-77/CWE-78) in the Replication Receiver component at /rps/api/json/UpdateReceivers.do, also reachable through manipulation of the 'random' argument, yielding unauthenticated command execution in the context of NT AUTHORITY\SYSTEM. CVE records rate CVE-2026-105134 at CVSS 3.1 10.0 and CVE-2026-105133 at CVSS 3.1 7.3 (Huntress labels them critical and medium respectively).

Huntress observed exploitation beginning 2026-10-07 at 23:20:15 UTC across at least five organizations as of 2026-10-08. Attackers chained the authentication bypass with the command injection to drop JSP webshells on the AhsayCBS host, then used the SYSTEM-level execution to download tooling from an Alibaba Cloud OSS bucket (imagefiles-backup.oss-ap-southeast-7.aliyuncs.com/javas/Office/win/), including certutil.exe-based retrieval of the vulnerable WinRing0x64.sys kernel driver used to boost mining performance.

Post-exploitation payloads: an XMRig Monero miner renamed edge.exe with config.json; a renamed NSSM (Non-Sucking Service Manager) binary named msedge.exe used to install a persistent Windows service named MicrosoftEdgeUpdateSvc that mimics the legitimate edgeupdate service; and Taskgmr.ps1, an apparently AI-assisted PowerShell script that monitors for Windows Task Manager, kills it (at 18:00 or if open more than an hour overnight), stops the mining service while Task Manager is open and restarts it on closure. Mining traffic goes to the pool xmr.kryptex.network port 8029 with worker identifier krxYMRN97D/creativejs. Huntress listed six IPs associated with the activity. No attribution to a named actor is made in the source; motivation is financial (cryptojacking), but webshell access allows secondary payloads, so Huntress recommends host re-imaging from trusted backups if compromise is found.

Version note: Huntress states AhsayCBS is affected 'through 10.3.4', whereas the CVE/VulDB records list 10.3.0-10.3.2 as vulnerable with 10.3.4 as the fixed release. These sources conflict; defenders should treat any version below the latest vendor release as exposed and verify against the Ahsay 10.3.4 release notes. Huntress published four Sigma rules covering unexpected child processes of cbssvcX64.exe/cbssvcX86.exe, edge-named binaries with daemonized flags or msedge_exe metadata, Task Manager-aware service control via PowerShell, and WinRing0 driver downloads via the command line.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1505.003 Web Shell
- T1543.003 Windows Service
- T1059.001 PowerShell
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1608.001 Upload Malware
- T1496.001 Compute Hijacking
- T1583.006 Web Services
- T1569.002 System Services: Service Execution
- T1057 Process Discovery
- T1105 Ingress Tool Transfer

## Sources

- [Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer (Huntress)](https://www.huntress.com/blog/ahsaycbs-flaws-exploit)
- [CVE-2026-105134 (OpenCVE)](https://app.opencve.io/cve/CVE-2026-105134)
- [CVE-2026-105133 (OpenCVE)](https://app.opencve.io/cve/CVE-2026-105133)
- [CVE-2026-105134 (Rapid7 Vulnerability Database)](https://rapid7.com/db/vulnerabilities/cve-2026-105134)
- [CVE-2026-105134 (VulDB 413351)](https://vuldb.com/vuln/413351)
- [Ahsay AhsayCBS v10.3.4 Release Notes](https://www.ahsay.com/en/support/help-centre/release-notes/cbs/v10.3.4)
- [CVE-2026-105134 (INCIBE-CERT)](https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2026-105134)
- [CVE-2026-105133 (INCIBE-CERT)](https://www.incibe.es/en/incibe-cert/early-warning/vulnerabilities/cve-2026-105133)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3109
