CVE Tools
Back to feed
Patch released Veeam Service Provider Console cloud Terraform MCP Server Veeam privilege-escalation

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

The Hacker News·By The Hacker News··7 min read
CVE Tools coverage

Vendors Veeam, HashiCorp, and the Django Software Foundation have issued patches for 11 critical vulnerabilities across their products. Among these, a high-risk cross-tenant issue in HashiCorp’s Terraform MCP Server received a maximum CVSS score of 10.0. Other notable flaws include an unauthenticated credential-extraction bug in Veeam Service Provider Console (CVE-2026-58073, CVSS 9.5) and a potentially exploitable file-write vulnerability in GeoDjango. All affected products—Terraform MCP Server, Veeam Service Provider Console, and Django—have available updates to resolve these issues. Operators are advised to apply the latest versions to prevent potential misuse.