Two vulnerabilities in AhsayCBS — CVE-2026-105133 (authentication bypass) and CVE-2026-105134 (OS command injection) — are being exploited in the wild, and no patch is available at the time of writing. If your organization runs Ahsay's backup platform, or if you are an MSP whose clients do, you are operating a pre-authenticated remote code execution target that sits on top of your most recovery-critical data. That combination is exactly what ransomware operators look for.
This is not a theoretical exposure. Backup infrastructure is the crown jewel of any intrusion: adversaries who control your backup server control your ability to recover. We have watched this pattern play out across the industry — attackers systematically enumerate, tamper with, or destroy backup repositories before detonating encryption. A remotely exploitable, unpatched, internet-reachable backup management console is not a vulnerability-management backlog item. It is an incident waiting for a timestamp.
Technical Analysis
Affected Products and Exposure
AhsayCBS (Ahsay Cloud Backup Suite) is a Java-based backup and replication platform widely deployed by managed service providers and SMB/mid-market organizations across Windows and Linux. The vulnerable component is the web-based management and user console — the same Tomcat/Java web tier that administrators use to manage backup jobs, and that end users often access for self-service restore.
Key exposure characteristics defenders should inventory immediately:
- The AhsayCBS web console commonly listens on TCP 8080 (HTTP) and 8443 (HTTPS) by default, and many MSP deployments expose it to the internet for client self-service access.
- The service runs under a Java process (
java/javaw, launched via the AhsayCBS service wrapper) — frequently with elevated privileges (LOCAL SYSTEM on Windows, root or a privileged service account on Linux) because backup software requires broad filesystem access. - Multi-tenant MSP deployments mean a single compromised CBS host can expose dozens of downstream client backup sets.
The Vulnerability Chain
The two CVEs chain together into a classic, high-impact exploit path:
- CVE-2026-105133 — Authentication Bypass. The attacker circumvents the login mechanism of the AhsayCBS web application, gaining access to authenticated functionality without valid credentials. No phishing, no password spraying, no prior access required.
- CVE-2026-105134 — OS Command Injection. From the now-authenticated context, the attacker injects arbitrary operating system commands through a vulnerable parameter or function in the application, which are executed by the underlying host with the privileges of the AhsayCBS service account.
The net effect: unauthenticated remote code execution, as a highly privileged service account, on the backup server. From there, a realistic intrusion path includes enumeration and exfiltration or destruction of backup repositories, deployment of persistence, credential harvesting from stored backup job configurations (backup servers routinely hold domain admin, NAS, vCenter, and cloud storage credentials), and lateral movement into the wider environment.
Exploitation Status
- Confirmed active exploitation in the wild. This is not a proof-of-concept-only situation; attackers are scanning for and hitting exposed AhsayCBS instances now.
- No vendor patch is currently available. Ahsay has not yet released a fixed version for either CVE, which means compensating controls are your only defense until a patch ships.
- Because exploitation is confirmed and a fix is absent, treat every internet-reachable AhsayCBS console as potentially already compromised and investigate accordingly, not just as a patching task.
Check CISA's Known Exploited Vulnerabilities catalog and Ahsay's official advisories daily — KEV listing will impose binding remediation deadlines for federal agencies and is a strong prioritization signal for everyone else.
Detection & Response
Because both CVEs target the web tier and result in command execution by the AhsayCBS Java process, your highest-fidelity detection surface is child processes spawned by the backup server's Java runtime. A backup application should essentially never launch shells, scripting engines, or reconnaissance utilities. This gives us a low-noise, high-confidence detection.
Sigma Rules
The following rules target the post-exploitation behavior of CVE-2026-105134 — OS commands executed as children of the AhsayCBS Java process. They are intentionally tight: backup software legitimately spawns very few child processes outside of its own agents, so this fires rarely and matters when it does.
---
title: AhsayCBS Java Process Spawning Shell or Scripting Engine
id: 3f8a2b71-9c4d-4e56-a1b2-8d7e6f5c4a3b
status: experimental
description: Detects the AhsayCBS Java runtime spawning command shells or scripting engines, consistent with post-exploitation of CVE-2026-105134 OS command injection. AhsayCBS backup operations do not normally spawn interactive shells or script interpreters as direct children of the web/service JVM.
references:
- https://www.securityweek.com/unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild/
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\java.exe'
- '\javaw.exe'
ParentCommandLine|contains:
- 'cbs'
- 'AhsayCBS'
- 'ahsay'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\regsvr32.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
- '\curl.exe'
- '\wget.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare. Custom pre/post backup scripts configured by administrators may invoke cmd.exe; tune against documented backup script paths
level: critical
---
title: AhsayCBS Java Process Spawning Shell on Linux
id: 7c1d4e92-2a6b-4f38-b9c1-5e3d7a8f6b2c
status: experimental
description: Detects the AhsayCBS Java runtime on Linux spawning shells, download utilities, or reconnaissance tools, consistent with exploitation of CVE-2026-105134 command injection.
references:
- https://www.securityweek.com/unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild/
- https://attack.mitre.org/techniques/T1059.004/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.execution
- attack.t1059.004
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- '/java'
ParentCommandLine|contains:
- 'cbs'
- 'AhsayCBS'
- 'ahsay'
selection_child:
Image|endswith:
- '/sh'
- '/bash'
- '/dash'
- '/zsh'
- '/curl'
- '/wget'
- '/nc'
- '/ncat'
- '/python'
- '/python3'
- '/perl'
- '/base64'
condition: selection_parent and selection_child
falsepositives:
- Rare. Admin-defined pre/post backup scripts; validate against documented script inventory
level: critical
---
title: Suspicious Reconnaissance Command Under Backup Service Account
id: 9e2b5c14-6d8a-4f17-c3b9-1a4e6d8f2c5b
status: experimental
description: Detects execution of reconnaissance, credential access, or defense-evasion commands commonly observed after backup server compromise, when run on hosts identified as AhsayCBS servers. Hunt-level rule to surface post-exploitation behavior following CVE-2026-105133/105134.
references:
- https://www.securityweek.com/unpatched-ahsaycbs-vulnerabilities-exploited-in-the-wild/
- https://attack.mitre.org/techniques/T1033/
- https://attack.mitre.org/techniques/T1082/
author: Security Arsenal
date: 2026/04/06
tags:
- attack.discovery
- attack.t1033
- attack.t1082
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\java.exe'
- '\javaw.exe'
- '\cmd.exe'
selection_recon:
CommandLine|contains:
- 'whoami'
- 'net user'
- 'net group'
- 'ipconfig /all'
- 'systeminfo'
- 'nltest /domain_trusts'
- 'vssadmin delete shadows'
- 'wbadmin delete'
- 'bcdedit'
condition: selection_parent and selection_recon
falsepositives:
- Legitimate administrative maintenance on backup servers; restrict alerting to AhsayCBS hosts via asset tagging
level: high
Microsoft Sentinel / Defender KQL
This hunt query surfaces child processes of the AhsayCBS Java runtime across your fleet — the single most reliable post-exploitation signal for CVE-2026-105134. A second section checks web-tier logs ingested via CommonSecurityLog (WAF, reverse proxy, or firewall) for request patterns consistent with command injection probes against AhsayCBS console ports.
// Hunt 1: Shells and tooling spawned by the AhsayCBS Java process
// High fidelity: AhsayCBS JVM should not spawn shells/scripting engines in normal operation
let SuspiciousChildren = dynamic(["cmd.exe","powershell.exe","pwsh.exe","mshta.exe","wscript.exe","cscript.exe","rundll32.exe","certutil.exe","bitsadmin.exe","curl.exe","wget.exe","sh","bash","nc","ncat","python","python3","perl"]);
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName in~ ("java.exe","javaw.exe","java")
| where InitiatingProcessCommandLine has_any ("cbs","AhsayCBS","ahsay")
| where FileName in~ (SuspiciousChildren)
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine,
InitiatingProcessFileName, InitiatingProcessCommandLine,
AccountName, SHA256, ReportId
| sort by TimeGenerated desc;
// Hunt 2: Web requests to AhsayCBS console ports containing command-injection metacharacters
// Requires WAF/reverse proxy/firewall logging ingested as CommonSecurityLog
CommonSecurityLog
| where TimeGenerated > ago(14d)
| where DestinationPort in (8080, 8443)
| where RequestURL has_any ("/cbs/", "ahsay")
or RequestContext has_any ("/cbs/", "ahsay")
| where RequestURL has_any ("%3B","%7C","%26%26","%60","$(",";id",";cat","|nc","%2Fbin%2F","cmd.exe","powershell","/etc/passwd","whoami")
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort,
RequestMethod, RequestURL, RequestContext, DeviceAction
| sort by TimeGenerated desc;
// Hunt 3: Unusual outbound network connections from AhsayCBS hosts
// Backup servers have predictable egress; new destinations deserve scrutiny
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where InitiatingProcessFileName in~ ("java.exe","javaw.exe","java")
| where InitiatingProcessCommandLine has_any ("cbs","ahsay")
| where RemoteIPType == "Public"
| summarize ConnectionCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
by DeviceName, RemoteIP, RemotePort, RemoteUrl
| where ConnectionCount < 50
| sort by FirstSeen desc;
Velociraptor VQL
Use this artifact to hunt across suspected AhsayCBS servers for active child processes of the JVM and recently created executables/scripts in AhsayCBS directories — a common post-exploitation drop location when attackers achieve command execution.
-- Hunt AhsayCBS hosts for suspicious child processes of the JVM and recently dropped files
-- Deploy scoped to servers identified as running AhsayCBS
-- Part 1: Live processes — shells/scripting engines under the AhsayCBS Java runtime
SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Ppid IN (
SELECT Pid FROM pslist()
WHERE Name =~ '(?i)javaw?'
AND CommandLine =~ '(?i)(cbs|ahsay)'
)
AND Name =~ '(?i)(cmd|powershell|pwsh|mshta|wscript|cscript|rundll32|certutil|sh|bash|curl|wget|nc|python|perl)'
-- Part 2: Recently created executables and scripts in AhsayCBS installation/temp paths
SELECT FullPath, Size, Mtime, Atime, Ctime
FROM glob(globs=['C:/Program Files/AhsayCBS/**', '/usr/local/cbs/**', '/opt/ahsay*/**'])
WHERE NOT IsDir
AND Mtime > now() - (14 * 24 * 3600)
AND FullPath =~ '(?i)\.(exe|dll|bat|ps1|sh|py|pl|jar|jsp|war)$'
ORDER BY Mtime DESC
Rapid Compromise Assessment
Before you close the ticket, verify the host is not already breached. On each AhsayCBS server:
#!/bin/bash
# AhsayCBS CVE-2026-105133 / CVE-2026-105134 rapid triage (Linux hosts)
# Run as root on the AhsayCBS server. Review output manually — this collects, it does not remediate.
echo "=== [1] AhsayCBS process tree (look for shells/tools under java) ==="
CBS_PID=$(pgrep -f 'java.*cbs' | head -1)
if [ -n "$CBS_PID" ]; then
ps --forest -g "$CBS_PID" -o pid,ppid,user,etime,cmd 2>/dev/null || \
pstree -ap "$CBS_PID"
else
echo "No AhsayCBS java process found — verify install path/service name."
fi
echo "=== [2] Listening ports (expect 8080/8443 bound to localhost only if hardened) ==="
ss -tlnp | grep -E ':(8080|8443)'
echo "=== [3] Recently modified files in CBS install and webapps dirs (last 14 days) ==="
find /usr/local/cbs /opt/ahsay* /opt/cbs -type f \
\( -name '*.jsp' -o -name '*.sh' -o -name '*.py' -o -name '*.jar' -o -name '*.war' \) \
-mtime -14 -ls 2>/dev/null
echo "=== [4] Web access log entries with command-injection metacharacters ==="
grep -RhiE '(%3b|%7c|%26%26|%60|cmd\.exe|powershell|/bin/(ba)?sh|/etc/passwd|whoami|\$\()' \
/usr/local/cbs/logs/ /opt/ahsay*/logs/ 2>/dev/null | tail -100
echo "=== [5] Suspicious scheduled persistence ==="
crontab -l 2>/dev/null
ls -la /etc/cron.d/ /var/spool/cron/ 2>/dev/null
systemctl list-timers --all 2>/dev/null | head -30
echo "=== [6] New local users / unexpected authorized_keys (last 14 days) ==="
awk -F: '($3 >= 1000 || $3 == 0) {print $1, $3, $6}' /etc/passwd
find /root /home -name 'authorized_keys' -mtime -14 -ls 2>/dev/null
echo "=== [7] Recent outbound connections from the CBS java process ==="
ss -tnp 2>/dev/null | grep -i java
echo "=== Triage complete. Preserve output before making changes. ==="
Remediation
There is no patch. Until Ahsay releases fixed versions for CVE-2026-105133 and CVE-2026-105134, your remediation plan is entirely compensating controls. Execute in this order:
1. Immediate (Today) — Remove the Attack Surface
- Take the AhsayCBS web console off the internet. This is the single most important action. If it must remain reachable, place it behind a VPN, an authenticated reverse proxy with IP allowlisting, or a zero-trust access gateway. An unauthenticated internet-facing console is the exploitation condition.
- Restrict console ports at the host firewall. Bind TCP 8080/8443 to localhost or a dedicated management VLAN reachable only from named admin workstations / jump hosts.
- Block outbound internet access from the AhsayCBS server except to explicitly required endpoints (your cloud storage targets, Ahsay licensing/update servers). Backup servers have no business browsing the internet, and egress filtering blunts C2 and exfiltration even if exploitation succeeds.
#!/bin/bash
# Emergency exposure reduction for AhsayCBS on Linux (iptables example)
# Goal: console ports reachable ONLY from the admin management subnet.
# Adjust MGMT_NET to your admin VLAN/jump host range. Test before cron/persist.
MGMT_NET="10.10.5.0/24"
for PORT in 8080 8443; do
iptables -C INPUT -p tcp --dport $PORT -s $MGMT_NET -j ACCEPT 2>/dev/null || \
iptables -I INPUT 1 -p tcp --dport $PORT -s $MGMT_NET -j ACCEPT
iptables -C INPUT -p tcp --dport $PORT -j DROP 2>/dev/null || \
iptables -A INPUT -p tcp --dport $PORT -j DROP
done
# Optional: default-deny outbound for the host, then re-allow only backup destinations
# (Populate with your actual storage/update endpoints before enabling.)
# iptables -A OUTPUT -p tcp -d <your-storage-endpoint> -j ACCEPT
# iptables -A OUTPUT -j DROP
iptables -L INPUT -n --line-numbers | grep -E '8080|8443'
echo "Verify console access from the management subnet, then persist rules."
2. Short-Term (This Week) — Harden and Verify
- Rotate every credential the backup server holds or has held: the AhsayCBS admin/system accounts, backup job credentials (domain/service accounts, NAS, vCenter, cloud storage keys), and any API tokens configured in the platform. Assume they were readable post-exploitation.
- Enforce MFA and strong unique passwords on all AhsayCBS console accounts; disable unused accounts. MFA will not stop the auth bypass itself, but it hardens the legitimate path and any post-fix attack surface.
- Run the compromise assessment above on every AhsayCBS host. If you find evidence of exploitation, treat it as a full incident: preserve forensic images, hunt laterally from the host, and review backup job integrity.
- Verify backup integrity out-of-band. Confirm recent restore tests from isolated copies, review job histories for unexpected deletions or retention changes, and alert on mass backup-set deletion.
- Subscribe to Ahsay's security advisories and support channels so the patch is applied within 24 hours of release. Monitor the CISA KEV catalog for addition of these CVEs.
3. When the Patch Ships — Apply and Re-Validate
- Apply the vendor fix as an emergency change; do not wait for a standard maintenance window. Pre-stage a rollback snapshot.
- After patching, re-run the exploitation preconditions: confirm the console is still network-restricted, re-scan externally, and re-run the detection content above for 14 days of retro-hunting.
- If you are an MSP, communicate patch status to every downstream tenant — a compromised CBS host is their incident too.
4. Strategic — Backup Infrastructure Deserves Its Own Security Tier
This incident reinforces a posture we've been recommending to clients for years: backup platforms should be treated as Tier-0 assets, on par with domain controllers. That means dedicated management networks, no direct internet exposure, immutable/offline backup copies (object lock, WORM, or air-gap), just-in-time admin access, and EDR coverage with custom detections like the ones above. The organizations that survive ransomware events are the ones whose backups the attacker never touched.
If you need help determining whether your AhsayCBS deployment was exposed or compromised, this is exactly the kind of engagement our IR team handles — from rapid compromise assessment to full forensic investigation.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.