# Huntress finds exploited AhsayCBS flaws persist in latest release

_Published Friday, October 9, 2026 at 2:37 PM EDT · Security · Latest · Tier 2 — Notable_

![Huntress finds exploited AhsayCBS flaws persist in latest release — Primary](https://www.bleepstatic.com/content/hl-images/2026/10/09/hacker-box.jpg)

Huntress said Friday that AhsayCBS 10.3.4, the latest version of the backup management platform, remains vulnerable to two flaws attackers are exploiting. Both had been reported as fixed in version 10.3.2. Attacks observed on October 7 targeted at least five organizations.

Attackers chained an authentication bypass with operating system command injection to execute code, install webshells and deploy a cryptocurrency miner. AhsayCBS is typically used by managed service providers and system integrators. Until a patch is available, Huntress recommends restricting the management interface to trusted IP addresses and checking for compromise. Confirmed compromises warrant a full host restore from a safe backup because additional backdoors may remain.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/)

---
Canonical: https://techandbusiness.org/newswire/x6azu6SAmZpJ3KF2PNQi-_
Published: 2026-10-09T18:37:54.426Z
Story chronology: 2026-10-09T17:17:23.000Z
Retrieved: 2026-10-09T20:36:21.854Z
Publisher: Tech & Business (techandbusiness.org)
