Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners.
Excerpt from the primary source: BleepingComputer
Who is affected
Small businesses · Security professionals
Why it matters
Source reporting says attackers are already exploiting this, so exposed affected systems are at immediate risk.
Automated: stated only from CISA listings and the exploitation evidence in the sources below.
What you should do · Mitigate
No complete fix is indicated yet. Apply the vendor's recommended workarounds for the affected products, limit exposure (for example, restrict internet access to management interfaces) and watch for a patch.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Original reporting
Related
Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands.
Source reporting says attackers are already exploiting this, so exposed Microsoft Edge systems are at immediate risk.
Treat this as an emergency.
Microsoft: Outdated Windows devices will stop receiving security updates
Microsoft says devices running unsupported versions of Windows will stop receiving security updates after next year's Windows Update certificate rotation.
Citrix warns admins to patch new NetScaler RCE flaw immediately
Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.
Apply the vendor's security update for NetScaler ADC / Gateway.
Citrix Urges Immediate Patching of Critical NetScaler Vulnerability
The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service.
Apply the vendor's security update for NetScaler ADC / Gateway.
