Threat reportVulnerabilityTL-2026-1891
August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and Django
August 2026 Patch Roundup (TL-2026-1891) is a critical-severity software vulnerability scored CVSS 10, first published 2026-08-05. It has no confirmed attribution, affects Veeam Service Provider Console (VSPC), references 11 CVEs (CVE-2026-58073, CVE-2026-58072, CVE-2026-58071), maps to 14 MITRE ATT&CK techniques (T1048, T1059, T1069), and is covered by 9 detection rules and 3 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 11Referenced vulnerabilities
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 3Indicators of compromise
Key facts for TL-2026-1891
- Threat ID
- TL-2026-1891
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- managed-service-providers, cloud-service-providers, web-application-hosting, enterprise-it, devops-platform-engineering
- Target regions
- Worldwide
- Detection rules
- 9
- Indicators of compromise
- 3
Malware and tooling in August 2026 Patch Roundup
Malware and tooling: Django, Python
How August 2026 Patch Roundup works
Eleven vulnerabilities disclosed across three major advisories — Veeam Service Provider Console (4 CVEs, fixed in build 9.3.0.35057), HashiCorp Terraform MCP Server (3 CVEs, fixed in v1.1.0), and Django (4 CVEs, fixed in 6.0.8/5.2.17). The most severe flaw (CVE-2026-16498, CVSS 10.0) enables unauthenticated cross-tenant credential reuse in HashiCorp's Terraform MCP Server running in stateless streamable-HTTP mode. None are under active exploitation or have public PoC as of August 5, 2026.
This patch roundup covers 11 CVEs across three distinct software products disclosed between July 28 and August 4, 2026. Patches are available from all three vendors.
## Veeam Service Provider Console (4 CVEs, Fixed in 9.3.0.35057)
VSPC is a multitenant cloud-based web portal for centralized management of Veeam backup agents and Veeam Backup & Replication in service-provider environments. Its architecture includes a VSPC Server, Web UI, Cloud Gateways for TLS-secured connectivity, and management agents that interact with client and infrastructure systems. All four flaws affect VSPC version 9 builds prior to 9.3.0.35057.
**CVE-2026-58073 (CVSS 4.0: 9.5, Critical)** — An authentication bypass (CWE-288) allowing an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials. The attack is network-accessible with high complexity, requires no privileges or user interaction, and impacts confidentiality, integrity, and availability across both vulnerable and subsequent systems. Reported via HackerOne. CISA SSVC assesses exploitation as none, not automatable, but technical impact is total. Credentials stored by VSPC for connection accounts and service accounts on managed systems — including local Administrator credentials on VBR servers, Cloud Connect servers, and client machines — are at risk of theft, enabling lateral movement into tenant environments.
**CVE-2026-58072 (CVSS 4.0: 9.0, Critical)** — A path-traversal arbitrary file write (CWE-22) on the VSPC management server that can lead to remote code execution. The attack requires low privileges but is network-accessible with low complexity. An authenticated attacker with the lowest privilege level can write files of their choosing to the VSPC server filesystem, potentially overwriting server binaries, configuration files, or planting web shells.
**CVE-2026-58067 (CVSS 4.0: 8.7, High)** — An unauthenticated memory-exhaustion denial-of-service (CWE-789) triggered over the network with low complexity. No privileges, user interaction, or protection bypass required. CISA SSVC flags this as automatable with partial technical impact — making it a viable availability risk for unpatched instances.
**CVE-2026-58071 (CVSS 4.0: 8.2, High)** — A missing-authentication (CWE-306) flaw exposing the proxied appliance API as Portal Administrator during a brief window after an administrator session begins. An unauthenticated attacker can obtain high confidentiality impact (read access to VSPC appliance data) during that session transition window.
## HashiCorp Terraform MCP Server (3 CVEs, Fixed in v1.1.0 / v1.2.0)
The terraform-mcp-server enables centralized, multi-user deployments of Terraform via a streamable-HTTP transport. It supports two modes — stateful (default, per-session caching of Terraform API clients) and stateless (each request independent, required for multiple replicas behind a load balancer). The server authenticates via bearer tokens for HCP Terraform or Terraform Enterprise. All three CVEs affect the streamable-HTTP transport only; stdio (local single-user) mode is unaffected. Affected versions: 0.2.1 through 1.0.0.
**CVE-2026-16498 (CVSS 3.1: 10.0, Critical)** — Cross-tenant credential reuse in stateless streamable-HTTP mode. The underlying MCP library does not assign unique session identifiers to requests in stateless mode, and the server's per-session credential cache relies on those absent IDs. Consequently, one user's Terraform token is applied to subsequent users' requests regardless of the credentials they supply. This means User A's token executes tool calls (listing organizations, workspaces, variables, running operations) as User B. CISA SSVC: exploitation none, automatable yes, technical impact total. Availability impact is low (the vulnerability primarily affects confidentiality and integrity).
**CVE-2026-16496 (CVSS 3.1: 8.9, High)** — Authorization bypass (CWE-384 Session Fixation) in stateful streamable-HTTP mode. The per-session Terraform client cache uses the MCP session ID as its sole lookup key without binding the cached client to the token that created it. A remote attacker who obtains another user's MCP session ID can supply it in their own requests and inherit the victim's cached credentials, gaining access to the victim's Terraform organizations, workspaces, variables, and other resources within the scope of that token's permissions. Requires no authentication to initiate but demands high attack complexity (obtaining another user's session ID). Reported by Juan Pablo Martinez Kuhn (Coinspect).
**CVE-2026-14869 (CVSS 3.1: 8.6, High)** — Server-Side Request Forgery (CWE-918) in the streamable-HTTP transport layer. Request middleware rejected a client-supplied Terraform address when provided as an HTTP header, but did not apply the same check when the same value was supplied as an HTTP query parameter. An unauthenticated attacker can redirect the server's Terraform API requests — including the server-side bearer token configured for server-authenticated deployments — to an attacker-controlled endpoint, exfiltrating the token. Found internally by HashiCorp. CISA SSVC: automatable.
## Django (4 CVEs, Fixed in 6.0.8 / 5.2.17, August 4, 2026)
**CVE-2026-15307 (CVSS 4.0: 8.7 / CVSS 3.1: 8.8, High)** — Server-side file write and request forgery via GeoDjango spatial lookups (CWE-73, CWE-918). The right-hand-side value in a spatial lookup is optimistically parsed by GDALRaster. A dict or its JSON-string representation is opened in write mode by file-backed GDAL drivers, enabling attacker-chosen file writes. Non-dict strings trigger outbound network requests through GDAL virtual filesystem handlers (SSRF). Critically, the Django admin changelist permits filtering via ModelAdmin.lookup_allowed(), meaning any staff user with view permission on a model containing a spatial field (GeometryField or RasterField) can trigger the vulnerability through the admin interface. Writing a file to a location later imported by the application can result in remote code execution. Fix: dict values and invalid GEOSGeometry strings are now rejected by spatial lookups (backward-incompatible). Reported by Bence Nagy, localhost-detect, and kimchunbok_.
**CVE-2026-15920 (CVSS 3.1: 6.1, Medium)** — Stored cross-site scripting (CWE-83) via URLField values in the Django admin. The admin's display_for_field() function renders URLField values as clickable links on changelist and read-only admin pages without URL validation. An attacker who can store a URLField value with a dangerous scheme (such as javascript:) can create an XSS vector against other admin users viewing the data. Fix: URLField values are now validated via URLValidator before rendering; non-http(s) schemes render as plain text. Reported by Egor Saltykov.
**CVE-2026-15830 (CVSS 4.0: 6.9 / CVSS 3.1: 5.3, Medium)** — Denial of service via deeply nested GEOMETRYCOLLECTION objects (CWE-674 Uncontrolled Recursion). Processing deeply nested GEOMETRYCOLLECTION WKT/WKB inputs triggers unbounded recursion and a segmentation fault in the GEOS library. Spatial field lookups, GeometryField form fields, and GEOSGeometry parsing are all affected. Fix: maximum depth limits of 198 collections enforced. CISA SSVC: automatable. Reported by Andrew MacPherson and kimchunbok_.
**CVE-2026-15337 (CVSS 4.0: 6.9 / CVSS 3.1: 5.3, Medium)** — Denial of service via memory consumption (CWE-789) in check_for_language(). When many distinct, very long language codes are supplied, each is retained as a key in an in-memory cache, consuming process memory. The attack surface goes through django.views.i18n.set_language() (not routed by default) via POST data. Mitigating factors: DATA_UPLOAD_MAX_MEMORY_SIZE caps request data, and the cache has a fixed maximum entry limit. Fix: language codes longer than 500 characters are now rejected before cached lookup. Reported by Jaeyoung Jang.
MITRE ATT&CK techniques used in TL-2026-1891
Exfiltration
T1048 Exfiltration Over Alternative Protocol
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Discovery
T1069 Permission Groups Discovery; T1087 Account Discovery
Persistence
T1078 Valid Accounts; T1505 Server Software Component
Command and Control
Collection
Initial Access
T1190 Exploit Public-Facing Application
Credential Access
T1528 Steal Application Access Token; T1555 Credentials from Password Stores
Lateral Movement
T1550 Use Alternate Authentication Material
Defense Evasion
Affected products and versions in August 2026 Patch Roundup
- Veeam — Service Provider Console (VSPC)
Vulnerable versions: All version 9 builds prior to 9.3.0.35057 (including 9.2.1.33875 and earlier)
Fixed in: 9.3.0.35057 and later - HashiCorp — Terraform MCP Server
Vulnerable versions: 0.2.1 through 1.0.0 (streamable-HTTP transport only)
Fixed in: 1.1.0 and later - Django Software Foundation — Django
Vulnerable versions: 5.2.x before 5.2.17; 6.0.x before 6.0.8; 6.1 RC (noted as affected); Older unsupported series 5.1.x, 5.0.x, 4.2.x may also be affected
Fixed in: 5.2.17; 6.0.8; 6.1 RC patched
Remediation for August 2026 Patch Roundup
Patches
- Veeam VSPC: KB4893 — build 9.3.0.35057 (released July 29, 2026)
- HashiCorp Terraform MCP Server: v1.1.0 (released July 14, 2026); v1.2.0 (August 4, 2026)
- Django 6.0.8 / 5.2.17 (released August 4, 2026)
Immediate actions
- Upgrade Veeam Service Provider Console to build 9.3.0.35057 or later (KB4893)
- Upgrade HashiCorp Terraform MCP Server to v1.1.0 or later (HCSEc-2026-23); v1.2.0 also available
- Upgrade Django to 6.0.8 or 5.2.17 for supported branches
Workarounds
- Veeam VSPC: limit network access to console and portal as interim measure
- HashiCorp: use stdio mode exclusively (unaffected); restrict network access to streamable-HTTP listener; treat MCP session IDs as sensitive
- Django: audit and restrict staff user GIS permissions as interim measure; disable GeoDjango-related admin views for untrusted staff users
Longer-term hardening
- Restrict network access to Veeam VSPC portal and management interfaces to trusted IP ranges only
- Restrict network access to Terraform MCP Server streamable-HTTP listener to trusted users only (workaround until patch)
- Treat MCP session IDs as sensitive values — enforce session ID rotation and token binding
- Audit Django admin staff user permissions — limit view/edit permissions on models with spatial fields to trusted users only
- Consider disabling GeoDjango spatial lookups if not required for business operations
- Implement runtime detection for GDALRaster-based exploitation attempts via spatial query monitoring
CVEs associated with August 2026 Patch Roundup
CVE-2026-58073, CVE-2026-58072, CVE-2026-58071, CVE-2026-58067, CVE-2026-16498, CVE-2026-16496, CVE-2026-14869, CVE-2026-15307, CVE-2026-15920, CVE-2026-15830, CVE-2026-15337
Weaknesses (CWE) in August 2026 Patch Roundup
CWE-288, CWE-22, CWE-306, CWE-789, CWE-488, CWE-384, CWE-918, CWE-73, CWE-674, CWE-83
Timeline of August 2026 Patch Roundup
- CVE-2026-58073 reserved by Veeam after initial HackerOne report; Veeam begins investigation into VSPC vulnerabilities. Other VSPC CVEs discovered during internal testing.
- HashiCorp releases Terraform MCP Server v1.1.0, fixing all three CVEs (CVE-2026-16498, CVE-2026-16496, CVE-2026-14869) in the streamable-HTTP transport.
- HashiCorp publishes HCSEc-2026-23 advisory detailing the three Terraform MCP Server vulnerabilities. Versions 0.2.1 through 1.0.0 affected; stdio mode unaffected; session IDs should be treated as sensitive.
- Veeam releases VSPC build 9.3.0.35057, fixing all four VSPC CVEs (CVE-2026-58073, CVE-2026-58072, CVE-2026-58071, CVE-2026-58067). Changelog notes HackerOne-reported authentication bypass and internal discoveries.
- NVD publishes entries for all 11 CVEs. CVE-2026-16498 receives CVSS 3.1 score of 10.0 (Critical); CVE-2026-58073 receives CVSS 4.0 score of 9.5 (Critical). CISA SSVC assessments show no active exploitation for any CVE.
- Veeam publishes KB4893 detailing all four VSPC CVEs. Django releases 6.0.8 and 5.2.17 fixing four CVEs (CVE-2026-15307, CVE-2026-15920, CVE-2026-15830, CVE-2026-15337). Multiple news outlets report the patch roundup.
- CISA Known Exploited Vulnerabilities catalog confirms none of the 11 CVEs are listed as actively exploited. All three vendors have patches available. HashiCorp releases Terraform MCP Server v1.2.0 with additional improvements.
Sources cited for August 2026 Patch Roundup
- The Hacker News — Veeam, Terraform MCP, Django Patch Roundup
- Veeam KB4893 — Critical Vulnerabilities in Veeam Service Provider Console
- HCSEC-2026-23 — Multiple Vulnerabilities in HashiCorp Terraform MCP Server
- Django 6.0.8 / 5.2.17 Security Release
- NVD — CVE-2026-58073 (Veeam VSPC Agent Impersonation, CVSS 9.5)
- NVD — CVE-2026-16498 (Terraform MCP Cross-Tenant Credential Reuse, CVSS 10.0)
- NVD — CVE-2026-15307 (Django GeoDjango File Write/RCE, CVSS 8.8)
- NVD — CVE-2026-16496 (Terraform MCP Session Cache Bypass, CVSS 8.9)
- NVD — CVE-2026-14869 (Terraform MCP SSRF, CVSS 8.6)
- NVD — CVE-2026-58072 (Veeam VSPC Arbitrary File Write, CVSS 9.0)
- NVD — CVE-2026-15920 (Django Stored XSS, CVSS 6.1)
- CISA Known Exploited Vulnerabilities Catalog
Detection coverage for TL-2026-1891
As of 2026-08-05, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1891 across Splunk SPL, Microsoft KQL and Sigma, covering 3 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.