GBHackers

Two AhsayCBS Zero-Day Vulnerabilities Actively Exploited to Take Over Backup Servers


Threat actors are exploiting two zero-day vulnerabilities in Ahsay Cloud Backup Server (AhsayCBS) to compromise exposed backup servers without authentication and execute commands with SYSTEM privileges.

Observed intrusions have deployed web shells and cryptocurrency miners, exposing weaknesses in the infrastructure that centrally manages backup operations.

According to Field Effect’s October 9, 2026, report, exploitation began late October 7. Researchers disclosed the activity on October 8 and identified five affected organizations within the first day of reporting.

Two AhsayCBS Zero-Day Vulnerabilities

The attack chain combines CVE-2026-105133, an improper authentication vulnerability in the checkSysPwd function with a CVSS score of 5.5, and CVE-2026-105134, an operating system command injection vulnerability in the Replication Receiver component rated 9.3.

Together, the flaws enable remote attackers to gain privileged execution without credentials or user interaction. AhsayCBS manages backup operations, storage destinations, user accounts, policies, and replication services.

Its Replication Receiver accepts replicated backup data from other systems, while associated application programming interfaces let administrators configure receiver settings and manage trusted replication partners.

Researchers showed that chaining the vulnerabilities lets an unauthenticated attacker configure a malicious replication receiver, deploy a Java Server Pages web shell, and run commands as NT AUTHORITYSYSTEM.

Successful exploitation requires network access to a vulnerable AhsayCBS interface, so externally accessible deployments are a priority to investigate. Observed attackers conducted reconnaissance and installed XMRig cryptocurrency miners disguised as Microsoft Edge processes.

They also created a fraudulent Edge update service for persistence and used PowerShell scripts intended to conceal mining activity from defenders. Web shells provided another way to execute commands on compromised hosts.

Although documented attacks focused on cryptomining, SYSTEM-level access creates broader risks. Depending on deployment permissions and integrations, attackers could access credentials, backup repositories, storage systems, and administrative functions.

Researchers did not report observing credential theft or backup manipulation in these intrusions. The potential impact increases when one deployment manages backups across multiple customers, locations, or business units.

Compromising that central administration point could threaten connected resources and undermine infrastructure needed for incident response and ransomware recovery.

Field Effect reported that versions through 10.3.4 remained vulnerable at disclosure. Administrators should inventory production, disaster recovery, test, and secondary deployments; verify versions; restrict management and replication access to trusted networks or VPNs; and install a vendor-fixed release when available.

Investigations should examine unexpected JSP files, suspicious child processes spawned by cbssvcX64.exe, unauthorized receiver configurations, PowerShell execution, and mining-related outbound connections.

Compromised hosts require checks for malicious services and persistence. Rebuild from known-good media and redeploy AhsayCBS to remove attacker modifications that application updates alone may leave behind.

Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team 



Source link