Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and the Django Software Foundation have released patches for 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and…
HashiCorp, Veeam, and the Django Software Foundation have released patches for 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and…
CVE-2026-16498 is a maximum-severity (CVSS 10.0) cross-tenant credential-reuse vulnerability in HashiCorp's Terraform MCP Server when running in stateless Streamable HTTP mode. The…
CVE-2026-16496 (CVSS 8.9) is a stateful-mode session isolation flaw in Terraform MCP Server. The credential cache uses the MCP session ID as…
CVE-2026-14869 (CVSS 8.6) is a server-side request forgery vulnerability in Terraform MCP Server's Streamable HTTP transport. Request middleware rejects a client-supplied Terraform…
HashiCorp released Terraform MCP Server version 1.1.0 to address three vulnerabilities in the Streamable HTTP transport, including a CVSS 10.0 cross-tenant credential…
HashiCorp's Terraform MCP Server, which connects AI assistants to Terraform over the Model Context Protocol, had three vulnerabilities in its Streamable HTTP…