CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

August 5, 2026

HashiCorp, Veeam, and the Django Software Foundation have released patches for 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The most severe is a cross-tenant credential-reuse flaw in HashiCorp’s Terraform MCP Server (CVE-2026-16498) with a CVSS score of 10.0. Veeam’s Service Provider Console also received critical fixes, including an unauthenticated credential disclosure (CVE-2026-58073, CVSS 9.5) and an arbitrary file write leading to RCE (CVE-2026-58072, CVSS 9.0). Django patched a high-severity GeoDjango file write/RCE issue (CVE-2026-15307) along with several lower-severity flaws. No active exploitation has been reported, and none of the CVEs are in CISA’s Known Exploited Vulnerabilities catalog.

Operators are urged to update Terraform MCP Server to 1.1.0 or later, Veeam Service Provider Console to 9.3.0.35057, and Django to 6.0.8 or 5.2.17. Exposure is configuration-dependent: HashiCorp’s bugs affect Streamable HTTP mode, Veeam’s flaws affect version 9 builds before 9.3, and Django’s admin attack path requires a staff account with view permission on a model containing a spatial field.

CVEs: CVE-2026-16498, CVE-2026-16496, CVE-2026-14869, CVE-2026-58073, CVE-2026-58072, CVE-2026-58067, CVE-2026-58071, CVE-2026-15307, CVE-2026-15920, CVE-2026-15830, CVE-2026-15337, CVE-2026-32998

Companies: Veeam, HashiCorp, Django Software Foundation, CrowdSec, Coinspect

Products: Terraform MCP Server, Veeam Service Provider Console, Django, GeoDjango