News with an accent.

A server room with rows of black cabinets and a raised floor with perforated tiles.
Sala de servidores. Imagen de archivo.Carl Lender / Wikimedia Commons (CC BY 2.0) · Imagen de archivo
Privacy

AhsayCBS has no patch and is under attack at five organizations

Two flaws let attackers take over the backup server without a password. Huntress saw the intrusions, and the latest version is also affected.

Two vulnerabilities in AhsayCBS, a platform for managing backups, are being exploited with no patch available. The security firm Huntress saw the first attacks on Oct. 7 and, as of Oct. 8, counted five affected organizations.

The four facts about the flaws:

  • CVE: CVE-2026-105133 (medium severity, improper authentication) and CVE-2026-105134 (critical, unauthenticated remote code execution with SYSTEM privileges).
  • Product: AhsayCBS, the central server used mostly by managed service providers and integrators.
  • Version: up to and including 10.3.4. The NVD, the U.S. government's vulnerability database, initially said that version was not affected, and Huntress found that it is.
  • Patch: none. Huntress notified Ahsay, and BleepingComputer reports that the company did not answer its inquiry before publication.

Because no patch exists, this article does not describe how the flaws are exploited.

What the attackers did

According to Huntress, the NVD published the two CVEs on Oct. 4. The first attack it saw happened on Oct. 7 at 23:20 UTC. After getting in, the attackers did reconnaissance, installed *webshells* (hidden remote access tools) and deployed a cryptocurrency miner disguised as a Microsoft Edge component. BleepingComputer adds that in one case they loaded a vulnerable driver to give the miner more of the machine's resources.

Access to this console matters more than usual, because AhsayCBS often manages the backups of many clients at once.

What Huntress recommends

The firm advises that the management console respond only to trusted IP addresses, or require a VPN connection, until a fixed version exists. If signs of compromise appear, it says to rebuild the whole machine from a trusted backup, because the attackers may have left additional access. Huntress published indicators of compromise and four Sigma detection rules.

It is still unknown whether Ahsay will release a patch and when, how many more organizations are affected and whether there are cases in Mexico. Huntress is the source of the attack reports and BleepingComputer reports them based on its analysis, so the two are not independent of each other.

Keep reading

El Mediático counts visits without cookies, with its own measurement and with Google Analytics, which receives basic data about your visit. Only if you accept does Google Analytics also store cookies and, where advertising is active, show personalized ads. You can accept all, reject all, or choose what to allow. The cookie policy is available in Spanish only. More about cookies (Spanish)