The active exploitation of vulnerabilities in AhsayCBS highlights a particularly concerning cybersecurity risk: the compromise of infrastructure that organizations depend upon for data protection and disaster recovery. Researchers have identified attackers chaining CVE-2026-105133, an authentication bypass vulnerability, with CVE-2026-105134, a critical operating system command injection flaw, to gain unauthorized access and execute malicious commands on vulnerable backup servers.

What makes this incident especially concerning is that the attackers are not simply exploiting the vulnerabilities for temporary access. They are deploying Java Server Page (JSP) webshells, establishing persistence through services disguised as legitimate Microsoft Edge components and installing XMRig cryptocurrency miners. Researchers also observed a PowerShell script, potentially developed with AI assistance, that monitors Windows Task Manager and temporarily stops mining activity when an administrator attempts to inspect running processes.

The implications extend beyond unauthorized cryptocurrency mining. Backup management servers frequently operate with privileged access to critical systems, backup repositories and sensitive organizational information. If compromised, they could potentially provide attackers with opportunities to interfere with backup operations, access protected data or undermine an organization's ability to recover from future cyber incidents. These broader risks are particularly significant for managed service providers responsible for protecting multiple customer environments.

Another troubling aspect is the reported uncertainty surrounding remediation. Although the vulnerabilities were initially believed to have been addressed in a newer release, subsequent investigation indicated that the latest AhsayCBS version remained affected. This reinforces why organizations cannot assume that installing the latest software version automatically eliminates every known exposure.

Enterprises and managed service providers should immediately review the exposure of their backup management interfaces, restrict access to trusted networks, investigate suspicious processes and services, and monitor for unauthorized command execution and outbound connections. Where compromise is identified, restoring from a verified clean backup and reviewing all potential persistence mechanisms becomes essential.

The broader lesson is that backup infrastructure must be protected with the same rigor as production systems. Strong access controls, network segmentation, intrusion prevention, behavioral monitoring and continuous vulnerability assessment are critical.

A backup system is supposed to be the last line of defence when everything else fails. If attackers compromise that system first, the consequences can extend far beyond the initial intrusion.


Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. [...]

Source: Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto via Bleeping Computer — published 09 Oct 2026.