#4
SecurityWeek
general
October 09, 2026 at 10:23 UTC
Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
By Ionut Arghire
AI Summary
Two unpatched vulnerabilities in AhsayCBS backup management software — CVE-2026-105133 (authentication bypass) and CVE-2026-105134 (OS command injection) — are being actively exploited in the wild to deploy webshells and cryptocurrency miners. The combination of authentication bypass with command injection on backup infrastructure represents a critical exposure for affected organizations.
Relevance score: 88.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →