Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
PatchVeeam Service Provider ConsoleTerraform MCP ServerOur summary
Vendors Veeam, HashiCorp, and the Django Software Foundation have issued patches for 11 critical vulnerabilities across their products. Among these, a high-risk cross-tenant issue in HashiCorp’s Terraform MCP Server received a maximum CVSS score of 10.0. Other notable flaws include an unauthenticated credential-extraction bug in Veeam Service Provider Console (CVE-2026-58073, CVSS 9.5) and a potentially exploitable file-write vulnerability in GeoDjango. All affected products—Terraform MCP Server, Veeam Service Provider Console, and Django—have available updates to resolve these issues. Operators are advised to apply the latest versions to prevent potential misuse.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.