SecurityWeek reports that two unpatched vulnerabilities in AhsayCBS are being actively exploited in the wild. The first, CVE-2026-105133, is an authentication bypass flaw. The second, CVE-2026-105134, allows attackers to inject operating system commands. Together, these flaws could give an unauthenticated attacker significant control over an affected backup server.
The report does not specify which versions of AhsayCBS are affected or provide indicators of compromise. It also does not mention any vendor response or mitigation guidance beyond noting that the vulnerabilities remain unpatched. Organizations using AhsayCBS should treat the product as exposed and monitor for suspicious activity, while waiting for an official fix.
Because there is only one source, no independent confirmation or conflicting details are available. The key takeaway is that these are real, exploited flaws with no patch yet, making immediate defensive action important for any AhsayCBS deployment.