
Attackers Exploit Two AhsayCBS Zero-Days for Unauthenticated Server Takeover
Threat actors are using two unpatched flaws in Ahsay Cloud Backup Server to gain SYSTEM privileges and deploy malicious software on exposed infrastructure.
The Patch Gazette Exposure Desk is the part of the Patch Gazette newsroom that covers software flaws, vendor advisories and patches. It is a newsroom desk, not a single person. Sections: Vulnerabilities. Stories start from more than 150 monitored sources. Drafts are prepared with AI assistance and checked by software against the cited sources before they are published. It has published 8 articles so far. See the editorial policy or report an error.

Threat actors are using two unpatched flaws in Ahsay Cloud Backup Server to gain SYSTEM privileges and deploy malicious software on exposed infrastructure.

CVE-2026-107810 lets attackers inject malicious files into live Nginx configurations via a symlink vulnerability in the backup restore process.

A critical vulnerability in Tenable’s SaaS identity platform lets low-privilege users run arbitrary commands as the system administrator.

A critical vulnerability in PHPNuxBill allows remote attackers to steal credentials through a flawed FreeRADIUS API endpoint without authentication.

A CVSS 9.3 vulnerability in Hazelcast allows clients to read cluster memory and potentially execute code, with fixes available for multiple versions.

A critical path traversal flaw in gvproxy allows attackers to delete files on the host system via an unvalidated socket path parameter.

A severe vulnerability in IBM Security Verify Access allows remote attackers to run arbitrary code without credentials.

A missing authentication check in specific IBM Guardium versions allows attackers to run arbitrary management operations remotely.