{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/ahsay-systems/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ahsay:ahsaycbs:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-105134"},{"cvss":7.3,"id":"CVE-2026-105133"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=01552F8F-EE68-5958-8B08-C7BF7F992387\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["AhsayCBS (\u003c 10.3.4)","AhsayCBS (\u003c= 10.3.2)","AhsayCBS (\u003c= 10.3.4)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","authentication-bypass","remote-access"],"_cs_type":"advisory","_cs_vendors":["Ahsay","Ahsay Systems"],"content_html":"\u003cp\u003eAhsay AhsayCBS, a backup software solution, contains a critical security vulnerability (CVE-2026-105134) in the Replication Receiver component. The flaw exists within the /rps/api/json/UpdateReceivers.do endpoint, where the 'random' argument is processed in an insecure manner. An unauthenticated remote attacker can inject arbitrary OS commands by manipulating this argument, leading to complete unauthorized access and execution of code with the privileges of the AhsayCBS application. With a CVSS base score of 10.0, this vulnerability poses a severe risk to organizations using the affected software. Publicly available exploit code has been reported, significantly increasing the likelihood of exploitation. Administrators must upgrade to version 10.3.4 immediately to remediate the vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated remote attacker to execute arbitrary system commands, leading to full server compromise, data exfiltration, or deployment of additional malicious payloads such as ransomware. The impact is critical, affecting any environment where AhsayCBS is exposed to the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of AhsayCBS to version 10.3.4 or later immediately.\u003c/li\u003e\n\u003cli\u003eApply the rules below to identify exploitation attempts targeting the identified API endpoint.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the AhsayCBS management interface to trusted IP addresses only, especially for the Replication Receiver component.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T10:40:25Z","date_published":"2026-10-04T09:01:29Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ahsay-cbs-rce/","summary":"Ahsay AhsayCBS up to version 10.3.2 is vulnerable to unauthenticated remote OS command injection via the /rps/api/json/UpdateReceivers.do endpoint, enabling full system compromise.","title":"Unauthenticated Remote Code Execution in Ahsay AhsayCBS","url":"https://feed.craftedsignal.io/briefs/2026-10-ahsay-cbs-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Ahsay Systems","version":"https://jsonfeed.org/version/1.1"}