Threat reportVulnerabilityTL-2026-1891

August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and Django

criticalPATCHED

August 2026 Patch Roundup (TL-2026-1891) is a critical-severity software vulnerability scored CVSS 10, first published 2026-08-05. It has no confirmed attribution, affects Veeam Service Provider Console (VSPC), references 11 CVEs (CVE-2026-58073, CVE-2026-58072, CVE-2026-58071), maps to 14 MITRE ATT&CK techniques (T1048, T1059, T1069), and is covered by 9 detection rules and 3 indicators of compromise.

CVSS
10/10Critical
CVEs
11Referenced vulnerabilities
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
3Indicators of compromise

Key facts for TL-2026-1891

Threat ID
TL-2026-1891
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
managed-service-providers, cloud-service-providers, web-application-hosting, enterprise-it, devops-platform-engineering
Target regions
Worldwide
Detection rules
9
Indicators of compromise
3

Malware and tooling in August 2026 Patch Roundup

Malware and tooling: Django, Python

How August 2026 Patch Roundup works

Eleven vulnerabilities disclosed across three major advisories — Veeam Service Provider Console (4 CVEs, fixed in build 9.3.0.35057), HashiCorp Terraform MCP Server (3 CVEs, fixed in v1.1.0), and Django (4 CVEs, fixed in 6.0.8/5.2.17). The most severe flaw (CVE-2026-16498, CVSS 10.0) enables unauthenticated cross-tenant credential reuse in HashiCorp's Terraform MCP Server running in stateless streamable-HTTP mode. None are under active exploitation or have public PoC as of August 5, 2026.

This patch roundup covers 11 CVEs across three distinct software products disclosed between July 28 and August 4, 2026. Patches are available from all three vendors.

## Veeam Service Provider Console (4 CVEs, Fixed in 9.3.0.35057)

VSPC is a multitenant cloud-based web portal for centralized management of Veeam backup agents and Veeam Backup & Replication in service-provider environments. Its architecture includes a VSPC Server, Web UI, Cloud Gateways for TLS-secured connectivity, and management agents that interact with client and infrastructure systems. All four flaws affect VSPC version 9 builds prior to 9.3.0.35057.

**CVE-2026-58073 (CVSS 4.0: 9.5, Critical)** — An authentication bypass (CWE-288) allowing an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials. The attack is network-accessible with high complexity, requires no privileges or user interaction, and impacts confidentiality, integrity, and availability across both vulnerable and subsequent systems. Reported via HackerOne. CISA SSVC assesses exploitation as none, not automatable, but technical impact is total. Credentials stored by VSPC for connection accounts and service accounts on managed systems — including local Administrator credentials on VBR servers, Cloud Connect servers, and client machines — are at risk of theft, enabling lateral movement into tenant environments.

**CVE-2026-58072 (CVSS 4.0: 9.0, Critical)** — A path-traversal arbitrary file write (CWE-22) on the VSPC management server that can lead to remote code execution. The attack requires low privileges but is network-accessible with low complexity. An authenticated attacker with the lowest privilege level can write files of their choosing to the VSPC server filesystem, potentially overwriting server binaries, configuration files, or planting web shells.

**CVE-2026-58067 (CVSS 4.0: 8.7, High)** — An unauthenticated memory-exhaustion denial-of-service (CWE-789) triggered over the network with low complexity. No privileges, user interaction, or protection bypass required. CISA SSVC flags this as automatable with partial technical impact — making it a viable availability risk for unpatched instances.

**CVE-2026-58071 (CVSS 4.0: 8.2, High)** — A missing-authentication (CWE-306) flaw exposing the proxied appliance API as Portal Administrator during a brief window after an administrator session begins. An unauthenticated attacker can obtain high confidentiality impact (read access to VSPC appliance data) during that session transition window.

## HashiCorp Terraform MCP Server (3 CVEs, Fixed in v1.1.0 / v1.2.0)

The terraform-mcp-server enables centralized, multi-user deployments of Terraform via a streamable-HTTP transport. It supports two modes — stateful (default, per-session caching of Terraform API clients) and stateless (each request independent, required for multiple replicas behind a load balancer). The server authenticates via bearer tokens for HCP Terraform or Terraform Enterprise. All three CVEs affect the streamable-HTTP transport only; stdio (local single-user) mode is unaffected. Affected versions: 0.2.1 through 1.0.0.

**CVE-2026-16498 (CVSS 3.1: 10.0, Critical)** — Cross-tenant credential reuse in stateless streamable-HTTP mode. The underlying MCP library does not assign unique session identifiers to requests in stateless mode, and the server's per-session credential cache relies on those absent IDs. Consequently, one user's Terraform token is applied to subsequent users' requests regardless of the credentials they supply. This means User A's token executes tool calls (listing organizations, workspaces, variables, running operations) as User B. CISA SSVC: exploitation none, automatable yes, technical impact total. Availability impact is low (the vulnerability primarily affects confidentiality and integrity).

**CVE-2026-16496 (CVSS 3.1: 8.9, High)** — Authorization bypass (CWE-384 Session Fixation) in stateful streamable-HTTP mode. The per-session Terraform client cache uses the MCP session ID as its sole lookup key without binding the cached client to the token that created it. A remote attacker who obtains another user's MCP session ID can supply it in their own requests and inherit the victim's cached credentials, gaining access to the victim's Terraform organizations, workspaces, variables, and other resources within the scope of that token's permissions. Requires no authentication to initiate but demands high attack complexity (obtaining another user's session ID). Reported by Juan Pablo Martinez Kuhn (Coinspect).

**CVE-2026-14869 (CVSS 3.1: 8.6, High)** — Server-Side Request Forgery (CWE-918) in the streamable-HTTP transport layer. Request middleware rejected a client-supplied Terraform address when provided as an HTTP header, but did not apply the same check when the same value was supplied as an HTTP query parameter. An unauthenticated attacker can redirect the server's Terraform API requests — including the server-side bearer token configured for server-authenticated deployments — to an attacker-controlled endpoint, exfiltrating the token. Found internally by HashiCorp. CISA SSVC: automatable.

## Django (4 CVEs, Fixed in 6.0.8 / 5.2.17, August 4, 2026)

**CVE-2026-15307 (CVSS 4.0: 8.7 / CVSS 3.1: 8.8, High)** — Server-side file write and request forgery via GeoDjango spatial lookups (CWE-73, CWE-918). The right-hand-side value in a spatial lookup is optimistically parsed by GDALRaster. A dict or its JSON-string representation is opened in write mode by file-backed GDAL drivers, enabling attacker-chosen file writes. Non-dict strings trigger outbound network requests through GDAL virtual filesystem handlers (SSRF). Critically, the Django admin changelist permits filtering via ModelAdmin.lookup_allowed(), meaning any staff user with view permission on a model containing a spatial field (GeometryField or RasterField) can trigger the vulnerability through the admin interface. Writing a file to a location later imported by the application can result in remote code execution. Fix: dict values and invalid GEOSGeometry strings are now rejected by spatial lookups (backward-incompatible). Reported by Bence Nagy, localhost-detect, and kimchunbok_.

**CVE-2026-15920 (CVSS 3.1: 6.1, Medium)** — Stored cross-site scripting (CWE-83) via URLField values in the Django admin. The admin's display_for_field() function renders URLField values as clickable links on changelist and read-only admin pages without URL validation. An attacker who can store a URLField value with a dangerous scheme (such as javascript:) can create an XSS vector against other admin users viewing the data. Fix: URLField values are now validated via URLValidator before rendering; non-http(s) schemes render as plain text. Reported by Egor Saltykov.

**CVE-2026-15830 (CVSS 4.0: 6.9 / CVSS 3.1: 5.3, Medium)** — Denial of service via deeply nested GEOMETRYCOLLECTION objects (CWE-674 Uncontrolled Recursion). Processing deeply nested GEOMETRYCOLLECTION WKT/WKB inputs triggers unbounded recursion and a segmentation fault in the GEOS library. Spatial field lookups, GeometryField form fields, and GEOSGeometry parsing are all affected. Fix: maximum depth limits of 198 collections enforced. CISA SSVC: automatable. Reported by Andrew MacPherson and kimchunbok_.

**CVE-2026-15337 (CVSS 4.0: 6.9 / CVSS 3.1: 5.3, Medium)** — Denial of service via memory consumption (CWE-789) in check_for_language(). When many distinct, very long language codes are supplied, each is retained as a key in an in-memory cache, consuming process memory. The attack surface goes through django.views.i18n.set_language() (not routed by default) via POST data. Mitigating factors: DATA_UPLOAD_MAX_MEMORY_SIZE caps request data, and the cache has a fixed maximum entry limit. Fix: language codes longer than 500 characters are now rejected before cached lookup. Reported by Jaeyoung Jang.

MITRE ATT&CK techniques used in TL-2026-1891

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Discovery

T1069 Permission Groups Discovery; T1087 Account Discovery

Persistence

T1078 Valid Accounts; T1505 Server Software Component

Command and Control

T1090 Proxy

Collection

T1119 Automated Collection

Initial Access

T1190 Exploit Public-Facing Application

Credential Access

T1528 Steal Application Access Token; T1555 Credentials from Password Stores

Lateral Movement

T1550 Use Alternate Authentication Material

Defense Evasion

T1574 Hijack Execution Flow

Affected products and versions in August 2026 Patch Roundup

  • Veeam — Service Provider Console (VSPC)
    Vulnerable versions: All version 9 builds prior to 9.3.0.35057 (including 9.2.1.33875 and earlier)
    Fixed in: 9.3.0.35057 and later
  • HashiCorp — Terraform MCP Server
    Vulnerable versions: 0.2.1 through 1.0.0 (streamable-HTTP transport only)
    Fixed in: 1.1.0 and later
  • Django Software Foundation — Django
    Vulnerable versions: 5.2.x before 5.2.17; 6.0.x before 6.0.8; 6.1 RC (noted as affected); Older unsupported series 5.1.x, 5.0.x, 4.2.x may also be affected
    Fixed in: 5.2.17; 6.0.8; 6.1 RC patched

Remediation for August 2026 Patch Roundup

Patches

  • Veeam VSPC: KB4893 — build 9.3.0.35057 (released July 29, 2026)
  • HashiCorp Terraform MCP Server: v1.1.0 (released July 14, 2026); v1.2.0 (August 4, 2026)
  • Django 6.0.8 / 5.2.17 (released August 4, 2026)

Immediate actions

  • Upgrade Veeam Service Provider Console to build 9.3.0.35057 or later (KB4893)
  • Upgrade HashiCorp Terraform MCP Server to v1.1.0 or later (HCSEc-2026-23); v1.2.0 also available
  • Upgrade Django to 6.0.8 or 5.2.17 for supported branches

Workarounds

  • Veeam VSPC: limit network access to console and portal as interim measure
  • HashiCorp: use stdio mode exclusively (unaffected); restrict network access to streamable-HTTP listener; treat MCP session IDs as sensitive
  • Django: audit and restrict staff user GIS permissions as interim measure; disable GeoDjango-related admin views for untrusted staff users

Longer-term hardening

  • Restrict network access to Veeam VSPC portal and management interfaces to trusted IP ranges only
  • Restrict network access to Terraform MCP Server streamable-HTTP listener to trusted users only (workaround until patch)
  • Treat MCP session IDs as sensitive values — enforce session ID rotation and token binding
  • Audit Django admin staff user permissions — limit view/edit permissions on models with spatial fields to trusted users only
  • Consider disabling GeoDjango spatial lookups if not required for business operations
  • Implement runtime detection for GDALRaster-based exploitation attempts via spatial query monitoring

CVEs associated with August 2026 Patch Roundup

CVE-2026-58073, CVE-2026-58072, CVE-2026-58071, CVE-2026-58067, CVE-2026-16498, CVE-2026-16496, CVE-2026-14869, CVE-2026-15307, CVE-2026-15920, CVE-2026-15830, CVE-2026-15337

Weaknesses (CWE) in August 2026 Patch Roundup

CWE-288, CWE-22, CWE-306, CWE-789, CWE-488, CWE-384, CWE-918, CWE-73, CWE-674, CWE-83

Timeline of August 2026 Patch Roundup

  • CVE-2026-58073 reserved by Veeam after initial HackerOne report; Veeam begins investigation into VSPC vulnerabilities. Other VSPC CVEs discovered during internal testing.
  • HashiCorp releases Terraform MCP Server v1.1.0, fixing all three CVEs (CVE-2026-16498, CVE-2026-16496, CVE-2026-14869) in the streamable-HTTP transport.
  • HashiCorp publishes HCSEc-2026-23 advisory detailing the three Terraform MCP Server vulnerabilities. Versions 0.2.1 through 1.0.0 affected; stdio mode unaffected; session IDs should be treated as sensitive.
  • Veeam releases VSPC build 9.3.0.35057, fixing all four VSPC CVEs (CVE-2026-58073, CVE-2026-58072, CVE-2026-58071, CVE-2026-58067). Changelog notes HackerOne-reported authentication bypass and internal discoveries.
  • NVD publishes entries for all 11 CVEs. CVE-2026-16498 receives CVSS 3.1 score of 10.0 (Critical); CVE-2026-58073 receives CVSS 4.0 score of 9.5 (Critical). CISA SSVC assessments show no active exploitation for any CVE.
  • Veeam publishes KB4893 detailing all four VSPC CVEs. Django releases 6.0.8 and 5.2.17 fixing four CVEs (CVE-2026-15307, CVE-2026-15920, CVE-2026-15830, CVE-2026-15337). Multiple news outlets report the patch roundup.
  • CISA Known Exploited Vulnerabilities catalog confirms none of the 11 CVEs are listed as actively exploited. All three vendors have patches available. HashiCorp releases Terraform MCP Server v1.2.0 with additional improvements.

Sources cited for August 2026 Patch Roundup

Detection coverage for TL-2026-1891

As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1891 across Splunk SPL, Microsoft KQL and Sigma, covering 3 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
3 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats