AI description
CVE-2026-105134 is an operating system command injection vulnerability affecting the Replication Receiver component of the AhsayCBS backup utility, specifically within the `/rps/api/json/UpdateReceivers.do` endpoint. The flaw stems from the improper neutralization of user-supplied input, which allows remote attackers to manipulate the `random` argument. The affected API also contains an authentication bypass mechanism that permits a random token to substitute for valid credentials. Consequently, remote, unauthenticated attackers can exploit this vulnerability to execute arbitrary commands with system privileges (such as NT AUTHORITY\SYSTEM) on the host. In active campaigns, threat actors have been observed chaining CVE-2026-105134 with CVE-2026-105133—an improper authentication flaw in the utility's `checkSysPwd` function—to bypass authentication and achieve remote code execution. After gaining access, attackers configure a malicious replication receiver and drop Java Server Page (JSP) web shells into the application directory. These intrusions are typically followed by reconnaissance and the deployment of payloads, such as XMRig cryptocurrency miners disguised as Microsoft Edge processes, alongside evasion scripts designed to terminate mining activities if administrative monitoring tools are opened.
- Description
- A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised.
- Source
- cna@vuldb.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 9.3
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 10
- Impact score
- 6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Secondary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
- cna@vuldb.com
- CWE-77
- Hype score
- Not currently trending
💢AhsayCBS açığı CVE-2026-105134 artık aktif saldırılarda kullanılıyor: 10.3.4 sürümü de savunmasız Huntress'ın raporuna göre saldırganlar 7 Ekim 23:20 UTC'den bu yana kimlik doğrulama açığı CVE-2026-105133 ile komut enjeksiyonu açığı CVE-2026-105134'
@trsiberyazilim
10 Oct 2026
249 Impressions
1 Retweet
27 Likes
0 Bookmarks
0 Replies
0 Quotes
No patch yet. Attackers are chaining two AhsayCBS backup flaws, CVE-2026-105133 (auth bypass) and CVE-2026-105134 (command injection), to drop webshells and an XMRig miner named edge.exe. Huntress says the latest 10.3.4 is affected. Limit the admin UI to trusted IPs. #MSP #CVE h
@ai4cybersec
10 Oct 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚔️ AHSAYCBS ZERO-DAY EXPLOITS! Attackers chain auth bypass (CVE-2026-105133) & command injection (CVE-2026-105134) for SYSTEM RCE & evasive XMRig mining. Read full Blog: https://t.co/iAwNSgGCFy #Hacktober #CyberAwareness #sh3llc0d3 #shellcode #ZeroDay
@sh3ll_c0d3
10 Oct 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
AhsayCBS backup servers under attack: CVE-2026-105133 (auth bypass) plus CVE-2026-105134 (command injection) gives SYSTEM RCE. Attackers drop JSP webshells and XMRig posing as edge.exe. Limit the console to trusted IPs and hunt for compromise. #infosec https://t.co/Ioj1xVcmzw
@V0iD_0daY
10 Oct 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🐦 🚨 AhsayCBS backup software under active attack: CVE-2026-105134 (CVSS 10.0) chained with CVE-2026-105133 for unauthenticated RCE as SYSTEM, webshells + XMRig dropped. Patch 10.3.4 available. Also actively exploited: Atlassian CVE-2026-21589 (CVSS 9.3). #infosec #CVE #0da
@ita_ipo
10 Oct 2026
52 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Threat actors exploited AhsayCBS flaws CVE-2026-105133 and CVE-2026-105134 to drop webshells and XMRig miners, with a call to update to 10.3.4 and restrict access now. https://t.co/DXz4dR3EHh
@Cyber_O51NT
10 Oct 2026
607 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
CVE-2026-105134 (CVSS 9.3) chained with CVE-2026-105133 in AhsayCBS is actively exploited as a zero-day, dropping webshells and XMRig as edge.exe. Hunt TEMP for WinRing0x64.sys and Taskgmr.ps1. #DFIR_Radar https://t.co/C1WzYLSEBi
@DFIR_Radar
10 Oct 2026
141 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Zero-day chain CVE-2026-105133 and CVE-2026-105134 in AhsayCBS 10.3.4 drops JSP webshells and XMRig as edge.exe, persisting via MicrosoftEdgeUpdateSvc. #DFIR_Radar https://t.co/Uh5nr97V1h
@DFIR_Radar
10 Oct 2026
122 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
バックアップ管理者には、復旧の頼みまで狙われる嫌な話だ。 HuntressはAhsayCBSのCVE-2026-105133/CVE-2026-105134の実悪用を観測。認証回避とOS command injectionを連鎖させ、認証不要のRCEにつなげる攻撃だ。同社は10月8日
@connect24h
10 Oct 2026
626 Impressions
0 Retweets
5 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical Unpatched AhsayCBS Vulnerabilities (#CVE-2026-105133 & #CVE-2026-105134): Active Exploitation and Hardening Guide + Video -Prediction: 📈 1 Positive | 📉 1 Negative https://t.co/tTdJmGwKdr Educational Purposes!
@UndercodeUpdate
10 Oct 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining CVE-2026-105133 + CVE-2026-105134 in AhsayCBS to bypass auth, drop web shells and deploy XMRig miners. Patch and hunt now. #Cybersecurity #InfoSec #CVE https://t.co/iWGhb2KZAL
@CyberWorldOps
9 Oct 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2025-57819 (CVSS: 10) FreePBX CVE-2026-105134 (CVSS: 10) Ahsay CVE-2026-40281 (CVSS: 10) gotenberg CVE-2024-40453 (CVSS: 9.8) CVE-2026-39987 (CVSS: 9.3) marimo-team ..🧵👇
@exploitgrid
7 Oct 2026
306 Impressions
1 Retweet
6 Likes
1 Bookmark
1 Reply
0 Quotes
ExploitGrid Daily Digest 🚨 Top CVEs: CVE-2026-105134 (CVSS: 10) Ahsay CVE-2026-105135 (CVSS: 10) InternLM CVE-2026-103355 (CVSS: 9.3) Unlimited El... CVE-2026-105086 (CVSS: 9.3) wwbn CVE-2026-105089 (CVSS: 9.3) wwbn ..🧵👇
@exploitgrid
5 Oct 2026
349 Impressions
1 Retweet
6 Likes
0 Bookmarks
1 Reply
0 Quotes
🔐 AhsayCBS Cluster — 2 CVEs, CVSS 10.0 Unauthenticated OS Command Injection in Replication Receiver Two vulnerabilities in Ahsay AhsayCBS were disclosed on October 3, 2026. CVE-2026-105134 (CVSS 10.0) Fixed in 10.3.4. 🔗 https://t.co/FRmBlpI1Ty #CyberSecurity #ThreatIn
@ThreatAft
4 Oct 2026
39 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes