VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_bf12718855e8aa2ad5138a0059961091

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Published Aug 5, 2026

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.

The three most serious:

An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5 A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'

Affected AI Products

mcp server
Get the weekly digest. Every Monday: top AI security stories of the week. Free.