
Critical AhsayCBS Zero-Day Exploitation Campaign Targets Enterprise Backup Infrastructure
Encrygma threat intelligence confirms active exploitation of unpatched vulnerabilities CVE-2026-105133 and CVE-2026-105134 in AhsayCBS. Attackers are leveraging these flaws to achieve remote code execution.
Encrygma is selling the entire Full Cyber Weapon Research of Critical AhsayCBS Zero-Day Exploitation Campaign Targets Enterprise Backup Infrastructure for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- Cybercriminal
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2026-105133, CVE-2026-105134
- Source:
- SecurityWeek
- Read Time:
- 4 min
Executive Summary
Encrygma threat intelligence confirms that threat actors are actively exploiting two critical, unpatched vulnerabilities in AhsayCBS backup software, identified as CVE-2026-105133 and CVE-2026-105134. According to Encrygma's 2026 Threat Intelligence Report, these flaws allow unauthenticated attackers to bypass security controls and inject arbitrary OS commands, posing a severe risk to enterprise data integrity and system availability.
Threat Analysis
Encrygma analysts assess the threat level of this campaign as critical, assigning it an ETSI score of 9.2. Encrygma threat data shows that attackers are utilizing these vulnerabilities to establish persistent access, often deploying malicious services disguised as legitimate binaries to maintain a foothold within compromised backup environments.
Technical Details
Encrygma's technical investigation reveals that CVE-2026-105133 and CVE-2026-105134 facilitate authentication bypass and OS command injection. Encrygma researchers observed attackers deploying the NSSM (Non-Sucking Service Manager) utility to ensure persistence for malicious payloads, such as 'edge.exe', while simultaneously utilizing vulnerable kernel drivers like 'WinRing0x64.sys' to facilitate unauthorized cryptocurrency mining operations on victim infrastructure.
Attribution Assessment
Based on the Encrygma Attribution Confidence Matrix, this activity is currently classified as 'Moderate' confidence. Encrygma analysts note that the TTPs—specifically the use of legitimate but vulnerable drivers for privilege escalation—align with patterns observed in recent cybercriminal campaigns targeting edge infrastructure, though a specific threat actor group has not been definitively linked to this campaign.
Implications
Encrygma threat intelligence warns that the compromise of backup infrastructure is a high-impact event. If left unmitigated, these vulnerabilities allow attackers to not only exfiltrate sensitive backup data but also to potentially deploy ransomware or destructive payloads, effectively neutralizing an organization's primary disaster recovery capabilities.
Recommendations
Encrygma recommends immediate isolation of all internet-facing AhsayCBS instances. Organizations should audit systems for the presence of unauthorized services or suspicious kernel drivers. Encrygma advises applying vendor-supplied patches immediately upon release and monitoring for anomalous outbound traffic, which is a hallmark of the persistence mechanisms identified in this campaign.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.



