🔴 Critical | Source: The Hacker News
HashiCorp, Veeam, and the Django Software Foundation have issued patches addressing 11 vulnerabilities, including two critical flaws: a CVSS 10.0 cross-tenant token reuse bug in HashiCorp’s Terraform MCP Server and a CVSS 9.5 unauthenticated credential exposure flaw in Veeam Service Provider Console. These vulnerabilities could allow attackers to hijack Terraform operations across tenant boundaries or extract managed agent credentials without authentication. Organisations using these tools in multi-tenant or service provider environments face significant exposure if unpatched.
Security Architect’s Take: Prioritise patching the Terraform MCP Server and Veeam Service Provider Console immediately — the cross-tenant token reuse flaw is particularly dangerous in shared or SaaS-style deployments where blast radius extends beyond a single customer. Audit recent Terraform MCP Server usage logs for any anomalous token activity that could indicate prior exploitation, and verify Veeam VSPC is not exposed to untrusted networks pending patching.
Original advisory: Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug