BlackTree Security · Infrastructure · Automation · AI

AhsayCBS 10.3.4 Was Still Affected

Apply 10.3.4.45, restrict management access and investigate earlier exposure.

Ahsay’s 10 October critical alert says 10.3.4.0 did not fully address CVE-2026-105133 and CVE-2026-105134. Version 10 partners should install the partner-only 10.3.4.45 hotfix and reboot.

For operators, the choice is narrower: deploy that hotfix, restrict management access and investigate whether the server was exposed before remediation. Patching does not establish integrity.

Why the correction matters

Huntress observed the chain from 23:20:15 UTC on 7 October. CVE-2026-105133 bypasses authentication; CVE-2026-105134 enables unauthenticated command execution through the replication receiver.

By 8 October, Huntress had seen five organisations targeted in its telemetry, not a global victim count. Observed activity included JSP webshells, XMRig miners and SYSTEM-level service persistence.

An 8 October Huntress update said testing also found 10.3.4 affected. The older CVE records still marked 10.3.4 unaffected after their 5 October updates. Ahsay’s 9 October clarification said 10.3.4.0 addressed the flaws; the 10 October alert superseded that position.

The dated source matters more than the bare version label. Use the current vendor alert for remediation, and retain the older records only for identifier and weakness context.

Patch, contain and investigate separately

BlackTree recommends four parallel decisions:

  1. Apply the vendor hotfix. Obtain 10.3.4.45 through Ahsay’s partner route, install it, reboot and verify every CBS node. Do not treat a public 10.3.4 installer as equivalent.
  2. Reduce exposure. Restrict the management interface to trusted administration addresses or require VPN access. Check firewalls, reverse proxies and cloud security groups as well as the application setting.
  3. Hunt before closing. Review unexpected child processes, new JSP files, Edge-named processes or services and miner traffic. Huntress published four Sigma rules for stages of the observed activity.
  4. Recover according to evidence. If indicators are present, isolate the host, preserve evidence and rebuild from a trusted backup before restoration. Ahsay warns that upgrading does not undo an earlier compromise. Rotate reachable credentials when the investigation shows exposure.

Patching removes a known route into the server. It does not prove that an already compromised server is trustworthy.

What the evidence does not show

The public Ahsay alert gives no global victim total, affected-organisation list or exact explanation of the 10.3.4.0 gap. The hotfix requires partner login, so BlackTree verified the public instruction but did not inspect the package.

Backup control planes sit close to credentials and recovery assets. BlackTree has made the same patch-versus-integrity distinction in its coverage of targeted exploitation against an Acronis backup integration and incident response for an exploited management interface.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *