AhsayCBS bugs exploited to deploy miners disguised as Microsoft Edge

Threat actors are exploiting two recently disclosed vulnerabilities in the AhsayCBS backup utility to take control of affected devices, deploy web shells and install XMRig cryptocurrency miners disguised as Microsoft Edge. Huntress said exploitation began on October 7, 2026, at 11:20 p.m. UTC, and estimated that five organizations had been affected by October 8.
The flaws are CVE-2026-105133, an improper-authentication issue with a CVSS v4 score of 5.5, and CVE-2026-105134, an operating-system command injection vulnerability rated 9.3. By chaining them, a remote attacker can bypass authentication and execute arbitrary commands on vulnerable systems.
Exposed management services are the entry point
CVE-2026-105133 affects the checkSysPwd() function in the com/ahsay/obs/api/ApiStructsAction.java component. CVE-2026-105134 is located in the Replication Receiver component. The CVE records were not published until October 4, but Huntress observed attackers weaponizing the pair only days later to achieve remote code execution on impacted hosts.
The campaign targets the externally accessible web application service on the AhsayCBS host. That makes the exposure of the management interface a central operational concern, particularly where it can be reached directly from the internet rather than only from trusted administration networks.
Miners attempt to evade routine checks
After gaining access, the operators conduct reconnaissance, drop web shells and deploy XMRig. The miner uses the filename edge.exe, impersonating the Microsoft Edge browser to reduce the likelihood of attracting attention during a cursory review of running processes.
Huntress also identified a PowerShell script named Taskgmr.ps1, launched through curl, that supports the cryptomining operation. The script is suspected to have been written with assistance from an AI tool and includes anti-analysis checks: it stops mining when a victim opens Windows Task Manager. It is also configured to terminate Task Manager at 6 p.m. when the application has remained open for more than an hour overnight.
In at least one incident, the attackers used the built-in certutil.exe utility to download the legitimate but vulnerable WinRing0x64.sys driver into the TEMP folder. Huntress said this was likely intended to obtain kernel-level access to the underlying hardware and optimise mining activity. The use of familiar process names and native Windows utilities resembles the evasion patterns in evasion patterns in endpoint attacks while placing particular emphasis on concealing sustained resource consumption.
No confirmed patch is available
National Vulnerability Database advisories state that the issues were addressed in AhsayCBS version 10.3.4. Huntress subsequently reported that version 10.3.4 is also vulnerable, effectively making the flaws zero-days.
Until a patch is available, Huntress recommends restricting AhsayCBS management-interface web access to trusted IP addresses or requiring a VPN. Businesses should review exposed AhsayCBS hosts for unexpected web shells, edge.exe processes, Taskgmr.ps1, suspicious certutil.exe downloads and other PowerShell activity, then limit management access before restoring affected systems to normal operation.

