Skip to main content
CyberReportedHighDevelopingFeatured
7.1

Unpatched AhsayCBS Flaws Exploited in Wild: Auth Bypass, RCE

Two unpatched vulnerabilities in AhsayCBS backup software, CVE-2026-105133 and CVE-2026-105134, are being actively exploited, enabling authentication bypass and OS command injection. The vendor has not yet released patches, leaving systems exposed. This is a notable escalation in targeted attacks against backup infrastructure, which is a high-value target for ransomware and data destruction campaigns.

SecurityWeekabout 12 hours agoengCredibility 26%View source

Score Breakdown

Mosaic Score7.1
Model confidence0.7
Significance0.8
Source credibility0.3
Source

Related signals

3 found