CVE-2026-105133
A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.
- CVSS
- 6.9
- EPSS
- 0.004 (30.3th percentile)
- CISA KEV
- Not listed
- Exploitation
- none
- Public exploits
- None seen
- State
- PUBLISHED
Coverage

The Hacker NewsSpecialist. Specialist publisher: established trade press, or expert analysis with a track record
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication…
SecurityWeekSpecialist. Specialist publisher: established trade press, or expert analysis with a track record
Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands. The post Unpatched AhsayCBS Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
HuntressAuthoritative. Authoritative publisher: a primary source, or a newsroom with formal editorial standards
Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
Threat actors are exploiting AhsayCBS flaws, including CVE-2026-105133 and CVE-2026-105134, to deploy webshells and XMRig cryptominers. Update to 10.3.4 and restrict access now.
What we observed
No signals recorded