Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Yes. Huntress reports that attackers began exploiting two AhsayCBS vulnerabilities on October 7, 2026, at 23:20:15 UTC. The attacks chained an authentication bypass with an unauthenticated remote code execution flaw, then installed a JSP webshell and an XMRig cryptominer named edge.exe that was set up to look like Microsoft Edge. As of Huntress’s October 8, 2026 update, it had seen five organizations targeted. That count reflects only the cases Huntress observed, not a total of affected organizations.

Patch status is the most time-sensitive part of this story. Huntress’s October 8 update corrected its earlier statement and says version 10.3.4 is also affected. At that time no patch was available, and Huntress recommended restricting access to the management interface while waiting for one. Check Ahsay’s own advisories before you treat any version as safe.

Which AhsayCBS versions are affected?

Huntress’s October 8 update says versions through 10.3.4 are affected. The first version of its report stated that 10.3.4 was not vulnerable. That statement was wrong, and the update corrects it. Do not treat 10.3.4 as a safe baseline.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The report did not identify a vendor-confirmed fixed version. If you run any AhsayCBS release in the affected range, assume exposure until Ahsay publishes a fix and you have confirmed that your build includes it. Until then, reducing exposure is the only control the report recommends.

#1 Best Overall

What is the attack chain?

Huntress describes two flaws used together:

  • CVE-2026-105133 is an improper-authentication issue involving the checkSysPwd function. In Huntress’s account, it bypasses authentication.
  • CVE-2026-105134 is a critical flaw in the Replication Receiver API endpoint /rps/api/json/UpdateReceivers.do. Huntress says it can enable unauthenticated remote code execution with NT AUTHORITY/SYSTEM privileges.

Once the attackers had code execution, they configured a malicious replication receiver and dropped a JSP webshell into the application directory. Huntress also saw AhsayCBS service processes spawning commands that downloaded files into temporary directories. Those downloads are what gave the attackers their miner and persistence tooling.

How the miner is disguised

Huntress lists the following files among those downloaded to compromised hosts. The table shows what each one is and what it was made to resemble.

File name What it is, per Huntress What it imitates
edge.exe XMRig cryptominer Microsoft Edge
msedge.exe Modified NSSM (service wrapper utility) Microsoft Edge
Taskgmr.ps1 PowerShell script that controls the miner service Not stated
config.json Downloaded file; purpose not detailed in the report Not stated
WinRing0x64.sys Known vulnerable driver, seen in one incident; Huntress says it appeared to support the miner’s hardware access in that case Not applicable

The modified NSSM binary ran as a service named MicrosoftEdgeUpdateSvc, which was designed to resemble the legitimate Edge Update service. The service ran with SYSTEM privileges and kept the miner running.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the script avoids detection

The PowerShell script watches for Task Manager. When Task Manager opens, the script stops the mining service so the high CPU use is not visible. When Task Manager closes, the script restarts the service. Huntress also says the script could terminate Task Manager at particular local times.

These are observations from the incident Huntress described. They are not proof that every compromised host had every component.

Mining traffic and indicators

Huntress reports miner connections to an XMR pool on port 8029, including xmr.kryptex[.]network and 51.195.127[.]124:8029. The report also contains further network indicators and payload hashes. Treat them as leads to check against your own logs, not as a complete list. The indicators are defanged in this article; re-fang them only in controlled tooling.

How to tell whether an AhsayCBS server is compromised

Look for these signs on the AhsayCBS host:

  • AhsayCBS service processes starting unexpected child processes, especially commands that download files.
  • Files named edge.exe or msedge.exe outside a standard Microsoft Edge install path, or a service named MicrosoftEdgeUpdateSvc that does not match a known Edge installation.
  • Files named Taskgmr.ps1 or config.json in temporary directories.
  • WinRing0x64.sys in a temporary folder.
  • A JSP webshell in the AhsayCBS application directory, or an unexpected malicious replication receiver in the AhsayCBS configuration.
  • Outbound connections to the mining pool endpoints listed above, or to port 8029.

Huntress links four Sigma rules that cover unexpected child processes from AhsayCBS, fake Edge-named binaries, Task Manager-aware service control, and WinRing0 driver downloads. Those rules can help you search for these behaviors in your environment. Test them against your own telemetry before relying on them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do if your AhsayCBS server is exposed

  1. Restrict access to the management interface now. Huntress recommends limiting web access to trusted IP addresses or requiring VPN access. Its stated reason: the exploit targets the externally reachable web application service on the host. In Huntress’s words, “Organizations should restrict AhsayCBS management interface web access, as the exploit targets the externally accessible web app service on the host.”
  2. Check for the indicators above. Search process, service, file, and network logs for the file names, service name, and pool endpoints, covering the period from October 7, 2026 onward.
  3. If you find indicators, treat the host as compromised. Huntress says secondary backdoors may be present, so cleaning the existing system is not enough. Reimage the host from a trusted backup taken before the compromise.
  4. Check Ahsay’s advisories before upgrading. Confirm which build contains the fix, and do not assume a version number is safe until the vendor says so.
  5. Review replication receiver configuration and the application directory. Look for receivers you did not create and any JSP files you do not recognize.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the evidence does and does not establish

The guidance rests on a single detailed incident report from Huntress, dated October 8, 2026, with the case count it reported as of that date. The report describes the campaign in detail, but this article has not independently verified the observations. It also does not establish current patch status. Patch availability, the affected version range, active exploitation, and the availability of indicators and rules can all change after publication.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.