Three major software vendors released security patches on Tuesday covering a combined 11 vulnerabilities, headlined by a maximum-severity cross-tenant flaw in HashiCorp’s Terraform MCP Server that earned a rare CVSS score of 10.0.
The critical Terraform MCP bug allows one user’s Terraform authentication token to be reused by subsequent users of the same server instance. In a shared or multi-tenant deployment, an attacker who obtains or guesses a previous session token could impersonate other organizations, read their infrastructure-as-code configurations, and potentially modify cloud resources without authorization.
Veeam addressed an unauthenticated vulnerability in its Service Provider Console that exposes managed agent credentials to remote attackers. Rated 9.5 on the CVSS scale, the flaw requires no authentication and gives an attacker immediate access to credentials used by backup agents, potentially allowing lateral movement across managed infrastructure and access to backup data.
The Django Software Foundation patched a third set of flaws in its widely used Python web framework. While none of the Django issues reached the severity of the other two, the combined disclosure underscores the breadth of the current patching cycle across infrastructure, backup, and application-layer software.
Together, the three advisories affect tools at the heart of modern cloud and DevOps workflows. Terraform is used to provision infrastructure across all major cloud providers. Veeam’s console is deployed by managed service providers to manage backup infrastructure for thousands of enterprises. Django powers websites and APIs for organizations ranging from startups to major platforms.
Security researchers noted that the Terraform MCP flaw is particularly dangerous because AI-assisted infrastructure management tools increasingly rely on MCP servers to execute Terraform operations. An attacker exploiting the cross-tenant token reuse could not only access existing configurations but potentially inject malicious infrastructure changes through AI workflows that trust the MCP server.
Organizations using any of the affected products should update immediately. Veeam has released patched versions of its Service Provider Console. HashiCorp has addressed the Terraform MCP Server flaw and recommends rotating all authentication tokens after upgrading. The Django Software Foundation released updates across its supported release branches.
The batch of disclosures arrives amid a broader surge in critical vulnerability patches across the software supply chain, with researchers reporting record numbers of flaws in cloud-native tooling, developer platforms, and AI infrastructure throughout 2026.
The Hacker News – Veeam, Terraform MCP, Django Patch Critical Flaws
Veeam Security Advisory KB4637
Sources: The Hacker News, Veeam Security Advisory, HashiCorp Security.
discussion