# Attackers exploit AhsayCBS flaws as latest version remains vulnerable

_Published Friday, October 9, 2026 at 11:07 AM EDT · Security · Latest · Tier 2 — Notable_

![Attackers exploit AhsayCBS flaws as latest version remains vulnerable — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMpbMY9pFBnt6TekKFIlEqpeqQoPBjBuhu8rYuYtU7ce5P3LTFKwlv_F_BUDzfuuMu0gRU645YStocoUQnNtS11MoEIRrfxrgPZtShsFgr8YH1VYTtjPr2l6aHPFDBYPHJKLT-fa-KqaHGSJHeiDPKzUgA12IJH5zhAHpMnoGZc5Qsz9sJhCOB_3gYHQar/s1700-nu-rw-lo-l85-e365/edge.jpg)

Attackers began exploiting two AhsayCBS backup software vulnerabilities on October 7 at 11:20 p.m. UTC, according to Huntress. The flaws can be chained to bypass authentication and execute commands remotely; five targeted organizations were estimated to have been affected as of October 8.

Huntress observed web shells and XMRig cryptocurrency miners disguised as Microsoft Edge. Although National Vulnerability Database advisories identify version 10.3.4 as fixed, Huntress says that version is also vulnerable. With no patch available, it recommends restricting the management interface to trusted IP addresses or requiring a VPN, and checking systems for signs of compromise.

## Sources

- [The Hacker News](https://thehackernews.com/2026/10/attackers-exploit-ahsaycbs-flaws-to.html)

---
Canonical: https://techandbusiness.org/newswire/amUq6BV7kQU87rLlvgj6O9
Published: 2026-10-09T15:07:22.940Z
Story chronology: 2026-10-07T23:20:00.000Z
Retrieved: 2026-10-09T17:32:12.526Z
Publisher: Tech & Business (techandbusiness.org)
