Cybersecurity researchers have identified active exploitation of two recently disclosed vulnerabilities in AhsayCBS, a backup management utility, with attackers using the flaws to gain control of affected systems and deploy web shells and cryptocurrency mining tools. According to Huntress, threat actors have exploited the vulnerabilities to execute unauthorized commands remotely, install XMRig cryptocurrency miners, and disguise mining activity as Microsoft Edge browser processes. The affected vulnerabilities include CVE-2026-105133, an improper authentication issue in the checkSysPwd() function of the AhsayCBS application, and CVE-2026-105134, an operating system command injection flaw affecting the Replication Receiver component. Researchers said attackers can combine the two vulnerabilities to bypass authentication protections and execute commands on vulnerable systems. The CVE identifiers for these issues were published on October 4, 2026, shortly before exploitation activity was observed.
Huntress reported that exploitation attempts targeting these vulnerabilities began on October 7, 2026, at 11:20 p.m. UTC, with unidentified attackers using the flaws to achieve remote code execution on impacted devices. By October 8, 2026, the cybersecurity company estimated that five organizations had been affected by the activity. Following successful access, attackers were observed conducting system reconnaissance, deploying web shells for continued access, and installing XMRig cryptocurrency miners. Huntress said the mining software was designed to avoid detection by using the filename “edge.exe,” making it appear similar to the Microsoft Edge browser process. Researchers also identified a PowerShell script named “Taskgmr.ps1” that supports the mining operation after being launched through curl. The script reportedly includes anti-analysis features designed to reduce visibility by monitoring Windows Task Manager activity and stopping mining processes when certain conditions are detected.
The PowerShell script observed during the investigation is suspected to have been created with assistance from an artificial intelligence tool and includes several measures intended to make analysis more difficult. According to Huntress, the script can stop mining operations when a user opens Windows Task Manager and is configured to terminate the Task Manager application if it remains open for an extended period overnight. Researchers also found that attackers used legitimate Windows utilities during at least one observed incident. The built-in certutil.exe tool was reportedly used to download a vulnerable but legitimate driver called WinRing0x64.sys into the system’s temporary directory. The activity suggests attackers may have attempted to gain deeper system access and improve mining performance by interacting with hardware at a lower level. While the activity primarily focused on cryptocurrency mining, the ability to execute commands remotely creates additional risks for organizations using vulnerable AhsayCBS installations.
The National Vulnerability Database advisories indicate that the vulnerabilities have been addressed in AhsayCBS version 10.3.4. However, Huntress noted that the issues were also affecting environments where exploitation had already started, effectively making them active zero day concerns for some users. The cybersecurity company recommended organizations reduce exposure by restricting access to the AhsayCBS management interface and limiting connectivity to trusted IP addresses or requiring VPN access. Organizations using the affected software are also advised to review systems for signs of compromise, check for unexpected processes such as disguised mining applications, and investigate unusual web shell activity. Huntress later confirmed an additional incident involving similar techniques but stated that there was no evidence of wider exploitation beyond the observed cases at the time of reporting. The incident highlights the importance of timely security updates, restricted administrative access, and continuous monitoring of backup infrastructure, which remains a valuable target for attackers seeking access to enterprise environments.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





