SECURITYTHE HACKER NEWS
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and the Django Software Foundation patched 11 vulnerabilities across their products, including a CVSS 10.0 cross-tenant flaw in HashiCorp's Terraform MCP Server and a high-severity unauthenticated credential-exposure flaw in Veeam's console.
Mentioned
Related Signal
Adjacent reporting
- Bug hunter tracks down three massive MCP flaws and one vendor won't fix theirs
- Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day
- cPanel, WHM Release Fixes for Three New Vulnerabilities — Patch Now
- Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover