Severity: HighAction: MitigateExploitation: Exploited

Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners.

Excerpt from the primary source: BleepingComputer

Who is affected

Small businesses · Security professionals

Why it matters

Source reporting says attackers are already exploiting this, so exposed affected systems are at immediate risk.

Automated: stated only from CISA listings and the exploitation evidence in the sources below.

What you should do · Mitigate

No complete fix is indicated yet. Apply the vendor's recommended workarounds for the affected products, limit exposure (for example, restrict internet access to management interfaces) and watch for a patch.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Original reporting

Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto BleepingComputer · bleepingcomputer.com · Oct 9, 2026 · Primary source
Severity: CriticalAction: Act nowExploitation: Exploited

Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands.

Why it matters

Source reporting says attackers are already exploiting this, so exposed Microsoft Edge systems are at immediate risk.

Act now

Treat this as an emergency.

Severity: HighAction: Patch

Citrix warns admins to patch new NetScaler RCE flaw immediately

Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions.

Patch

Apply the vendor's security update for NetScaler ADC / Gateway.