Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
Hackers are actively exploiting two unpatched AhsayCBS vulnerabilities, CVE-2026-105133 and CVE-2026-105134, to achieve unauthenticated remote code execution, deploy webshells, and gain persistence on exposed systems. Huntress says at least five organizations have been targeted, with attackers also installing XMRig miners, abusing a vulnerable driver, and disguising malicious components as Microsoft Edge. #AhsayCBS #CVE-2026-105133 #CVE-2026-105134 #XMRig #WinRing0x64.sys #NSSM

Keypoints

  • Two unpatched AhsayCBS flaws are being used for remote code execution.
  • The bugs allow authentication bypass and OS command injection.
  • Huntress observed webshell deployment on exposed systems.
  • Attackers installed XMRig miners and used stealthy persistence methods.
  • Organizations should restrict access to the AhsayCBS management interface immediately.

Read More: https://www.securityweek.com/unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild/