
RAPID RESPONSE: Huntress has detected active exploitation of CVE-2026-105133 and CVE-2026-105134—two recently disclosed vulnerabilities enabling remote code execution in the AhsayCBS backup utility—across five customer environments. 🧵
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A vulnerability was detected in Ahsay AhsayCBS up to 10.3.2. This affects the function checkSysPwd of the file com/ahsay/obs/api/ApiStructsAction.java of the component API. Performing a manipulation of the argument random results in improper authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 10.3.4 is able to mitigate this issue. It is recommended to upgrade the affected component.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

RAPID RESPONSE: Huntress has detected active exploitation of CVE-2026-105133 and CVE-2026-105134—two recently disclosed vulnerabilities enabling remote code execution in the AhsayCBS backup utility—across five customer environments. 🧵

Two 0days in AhsayCBS open a path from the internet to the corporate network. We walk through the full chain on Kill Chains and Coffee. Discovered by our Red Team Operator, Nick Cerne (@moodec0). CVE-2026-105133, CVE-2026-105134. Fixed in 10.3.4. 🎧 Listen wherever you get your podcasts: - YouTube: https://www.youtube.com/watch?v=aBLNBQ7ib78 - Spotify: https://open.spotify.com/show/5Xo3AYWGC8JgyGQRZz4YDO - Apple Podcasts: https://podcasts.apple.com/us/podcast/kill-chains-and-coffee/id6815755540 - Amazon Music: https://music.amazon.com/podcasts/7cb22247-1613-40fe-8195-d92e05188844/kill-chains-and-coffee iHeartRadio: https://iheart.com/podcast/346166309/