importantSYS.SOURCE: The Hacker News• 2026-08-05T19:57:30+05:30
Critical Vulnerabilities Patched in Veeam, Terraform MCP, and Django Including CVSS 10.0 Cross-Tenant Flaw
Veeam, Terraform MCP, and Django have addressed 11 vulnerabilities, including a critical CVSS 10.0 cross-tenant flaw in Terraform MCP that allows credential reuse across users. Critical issues in Veeam's console and Django's GeoDjango module also received patches, with fixes recommended for affected versions.
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.
The three most serious:
An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5 A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'
*** END OF TRANSMISSION ***