August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and Django — Threadlinqs Intelligence
As of 2026-08-05, August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and Django is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 3 indicators of compromise.
Threat ID: TL-2026-1891 · Severity: CRITICAL · CVSS: 10 · Status: PATCHED · Category: VULNERABILITY
Eleven vulnerabilities disclosed across three major advisories — Veeam Service Provider Console (4 CVEs, fixed in build 9.3.0.35057), HashiCorp Terraform MCP Server (3 CVEs, fixed in v1.1.0), and
This patch roundup covers 11 CVEs across three distinct software products disclosed between July 28 and August 4, 2026. Patches are available from all three vendors.
## Veeam Service Provider Console (4 CVEs, Fixed in 9.3.0.35057)
VSPC is a multitenant cloud-based web portal for centralized management of Veeam backup agents and Veeam Backup & Replication in service-provider environments. Its architecture includes a VSPC Server, Web UI, Cloud Gateways for TLS-secured connectivity, and management agents that interact with client and infrastructure systems. All four flaws affect VSPC version 9 builds prior to 9.3.0.35057.
**CVE-2026-58073 (CVSS 4.0: 9.5, Critical)** — An authentication bypass (CWE-288) allowing an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials. The attack is network-accessible with high complexity, requires no privileges or user interaction, and impacts confidentiality, integrity, and availability across both vulnerable and subsequent systems. Reported via HackerOne. CISA SSVC assesses exploitation as none, not automatable, but technical impact is total. Credentials stored by VSPC for connection accounts and service accounts on managed systems — including local Administrator credentials on VBR servers, Cloud Connect servers, and client machines — are at risk of theft, enabling lateral movement into tenant environments.
**CVE-2026-58072 (CVSS 4.0: 9.0, Critical)** — A path-traversal arbitrary file write (CWE-22) on the VSPC management server that can lead to remote code execution. The attack requires low privileges but is network-accessible with low complexity. An authenticated attacker with the lowest privilege level can write files of their choosing to the VSPC server filesystem, potentially overwriting server binaries, configuration files, or planting web shells.
**CVE-2026-58067 (CVSS 4.0: 8.7, High)** — An unauthenticated memory-exhaustion denial-of-service (CWE-789) triggered over the network with low complexity. No privileges, user interaction, or protection bypass required. CISA SSVC flags this as automatable with partial technical impact — making it a viable availability risk for unpatched instances.
**CVE-2026-58071 (CVSS 4.0: 8.2, High)** — A missing-authentication (CWE-306) flaw exposing the proxied appliance API as Portal Administrator during a brief window after an administrator session begins. An unauthenticated attacker can obtain high confidentiality impact (read access to VSPC appliance data) during that session transition window.
## HashiCorp Terraform MCP Server (3 CVEs, Fixed in v1.1.0 / v1.2.0)
The terraform-mcp-server enables centralized, multi-user deployments of Terraform via a streamable-HTTP transport. It supports two modes — stateful (default, per-session caching of Terraform API clients) and stateless (each request independent, required for multiple replicas behind a load balancer). The server authenticates via bearer tokens for HCP Terraform or Terraform Enterprise. All three CVEs affect the streamable-HTTP transport only; stdio (local single-user) mode is unaffected. Affected versions: 0.2.1 through 1.0.0.
**CVE-2026-16498 (CVSS 3.1: 10.0, Critical)** — Cross-tenant credential reuse in stateless streamable-HTTP mode. The underlying MCP library does not assign unique session identifiers to requests in stateless mode, and the server's per-session credential cache relies on those absent IDs. Consequently, one user's Terraform token is applied to subsequent users' requests regardless of the credentials they supply. This means User A's token executes tool calls (listing organizations, workspaces, variables, running operations) as User B. CISA SSVC: exploitation none, automatable yes, technical impact total. Availability impact is low (the vulnerability primarily affects confidentiality and integrity).
**CVE-2026-16496 (CVSS 3.1: 8.9, High)** — Authorization bypass (CWE-384 Session Fixation) in stateful streamable-HTTP mode. The per-se
Weaknesses (CWE)
CWE-288, CWE-22, CWE-306, CWE-789, CWE-488, CWE-384, CWE-918, CWE-73, CWE-674, CWE-83
Target sectors: managed-service-providers, cloud-service-providers, web-application-hosting, enterprise-it, devops-platform-engineering
Target regions: Worldwide
Related threats
- Multiple JetBrains Product Vulnerabilities: Account Takeover, Privilege Escalation, and RCE Across Hub, YouTrack, IntelliJ IDEA, Kotlin, GoLand, and TeamCity
- SolarWinds Serv-U 2026.3 Patches 16 Vulnerabilities (CVE-2026-28302 to CVE-2026-28321) Including Root RCE, IDOR-Chained Privilege Escalation, and Broken Access Control
- CVE-2026-56155: Microsoft AD FS Elevation-of-Privilege Vulnerability Actively Exploited
- Roundcube Webmail Pre-Auth SQL Injection in virtuser_query Plugin (CVE-2026-48842) — Patched in 1.6.16 / 1.7.1 Alongside 7 Other Vulnerabilities
- Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data Exfiltration
- Origin-Validation Bypass in Connective (Nitro Software Belgium) eID Browser Extension Enables PIN Theft, Signature Forgery, and Drive-By RCE Across 2M+ Belgian Users
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 3 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-58073, CVE-2026-58072, CVE-2026-58071, CVE-2026-58067, CVE-2026-16498, CVE-2026-16496, CVE-2026-14869, CVE-2026-15307, CVE-2026-15920, CVE-2026-15830, T1190, T1059, T1204, T1078, T1505, T1574, T1555, T1528, T1087, T1069