AhsayCBS Version 10.3.4 Confirmed Vulnerable to Exploits Using AI-Assisted Evasion Scripts

Managed Service Providers (MSPs) and enterprises using AhsayCBS backup management servers are facing active exploitation of two unpatched vulnerabilities that allow for unauthenticated remote code execution (RCE). Security researchers confirmed on October 8, 2026, that AhsayCBS version 10.3.4—which was initially believed to be a secure version—is susceptible to the attack chain. As of October 10, 2026, no official vendor patch is available from Ahsay Systems Corporation.

The exploitation involves chaining two distinct flaws: CVE-2026-105133 and CVE-2026-105134. The first is a medium-severity authentication bypass (CVSS 5.5), while the second is a critical OS command injection vulnerability with a CVSS score of 9.3. When combined, these vulnerabilities allow a remote, unauthenticated attacker to execute arbitrary commands with NT AUTHORITY\SYSTEM privileges, the highest level of access on a Windows system.

AI-Assisted Evasion and Stealth Tactics

A notable aspect of these attacks is the deployment of a PowerShell script titled Taskgmr.ps1. Analysts reported that the script appears to be AI-assisted, designed specifically to evade detection by human administrators. The script monitors the system for the presence of Windows Task Manager; if it detects the utility has been opened, it immediately suspends malicious processes or shuts down the mining activity to prevent visual detection of high CPU usage.

This evasion technique is used to protect the primary payload: an XMRig cryptocurrency miner. To further blend into the environment, the miner is frequently renamed to edge.exe, masquerading as a legitimate Microsoft Edge browser process. Threat actors have also been observed deploying a Java-based webshell, typically named cmd.jsp, to maintain persistent access to the compromised server.

The discovery that version 10.3.4 is vulnerable has shifted the risk profile for organizations that recently updated their software. According to researchers at Huntress, at least five organizations were confirmed targets of this exploitation chain by the second week of October. Because AhsayCBS vulnerabilities often reside in centralized management hubs, a single compromise can provide an entry point into the backup data of multiple downstream clients.

Mitigation and Detection

With no official patch currently available, security professionals recommend several immediate steps to reduce the attack surface. Administrators should consider restricting access to the AhsayCBS web interface by placing it behind a VPN or utilizing strict IP allow-listing. Since the attack results in SYSTEM-level privileges, monitoring for unusual child processes spawned by the Ahsay service—particularly PowerShell or Java processes—is critical for detection.

Security teams can also hunt for indicators of compromise (IoCs) by searching for the Taskgmr.ps1 script or non-standard edge.exe binaries running from unusual directories. Organizations are advised to monitor the official Ahsay support channels for a forthcoming security update to address the underlying command injection and authentication bypass flaws.

More From Category

More Stories Today