Skip to main content
Clarification on AhsayCBS v10.3.4.0 vulnerabilities

We have recently received inquiries from various sources regarding the following two vulnerabilities, both of which were addressed in AhsayCBS v10.3.4.0, released on 4 August 2026: 

https://vuldb.com/cve/CVE-2026-105133
https://vuldb.com/cve/CVE-2026-105134

We would like to clarify that partners who have already upgraded to v10.3.4.0 are no longer affected by these vulnerabilities and are protected against remote exploitation by unauthenticated attackers.

However, if your backup server was compromised prior to upgrading to v10.3.4.0, the upgrade itself would not resolve any issues arising from the compromise. In such cases, we strongly recommend engaging qualified cybersecurity professionals to conduct a thorough investigation and perform any necessary remediation activities.