# August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and Django

> Eleven vulnerabilities disclosed across three major advisories — Veeam Service Provider Console (4 CVEs, fixed in build 9.3.0.35057), HashiCorp Terraform MCP Server (3 CVEs, fixed in v1.1.0), and Django (4 CVEs, fixed in 6.0.8/5.2.17). The most severe flaw (CVE-2026-16498, CVSS 10.0) enables unauthenticated cross-tenant credential reuse in HashiCorp's Terraform MCP Server running in stateless streamable-HTTP mode. None are under active exploitation or have public PoC as of August 5, 2026.

- **Published:** 2026-08-05T00:00:00Z
- **Last reviewed:** 2026-08-05T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1891
- **ID:** TL-2026-1891
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 3 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-58073, CVE-2026-58072, CVE-2026-58071, CVE-2026-58067, CVE-2026-16498, CVE-2026-16496, CVE-2026-14869, CVE-2026-15307, CVE-2026-15920, CVE-2026-15830, CVE-2026-15337

## Description

This patch roundup covers 11 CVEs across three distinct software products disclosed between July 28 and August 4, 2026. Patches are available from all three vendors.

## Veeam Service Provider Console (4 CVEs, Fixed in 9.3.0.35057)

VSPC is a multitenant cloud-based web portal for centralized management of Veeam backup agents and Veeam Backup & Replication in service-provider environments. Its architecture includes a VSPC Server, Web UI, Cloud Gateways for TLS-secured connectivity, and management agents that interact with client and infrastructure systems. All four flaws affect VSPC version 9 builds prior to 9.3.0.35057.

**CVE-2026-58073 (CVSS 4.0: 9.5, Critical)** — An authentication bypass (CWE-288) allowing an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials. The attack is network-accessible with high complexity, requires no privileges or user interaction, and impacts confidentiality, integrity, and availability across both vulnerable and subsequent systems. Reported via HackerOne. CISA SSVC assesses exploitation as none, not automatable, but technical impact is total. Credentials stored by VSPC for connection accounts and service accounts on managed systems — including local Administrator credentials on VBR servers, Cloud Connect servers, and client machines — are at risk of theft, enabling lateral movement into tenant environments.

**CVE-2026-58072 (CVSS 4.0: 9.0, Critical)** — A path-traversal arbitrary file write (CWE-22) on the VSPC management server that can lead to remote code execution. The attack requires low privileges but is network-accessible with low complexity. An authenticated attacker with the lowest privilege level can write files of their choosing to the VSPC server filesystem, potentially overwriting server binaries, configuration files, or planting web shells.

**CVE-2026-58067 (CVSS 4.0: 8.7, High)** — An unauthenticated memory-exhaustion denial-of-service (CWE-789) triggered over the network with low complexity. No privileges, user interaction, or protection bypass required. CISA SSVC flags this as automatable with partial technical impact — making it a viable availability risk for unpatched instances.

**CVE-2026-58071 (CVSS 4.0: 8.2, High)** — A missing-authentication (CWE-306) flaw exposing the proxied appliance API as Portal Administrator during a brief window after an administrator session begins. An unauthenticated attacker can obtain high confidentiality impact (read access to VSPC appliance data) during that session transition window.

## HashiCorp Terraform MCP Server (3 CVEs, Fixed in v1.1.0 / v1.2.0)

The terraform-mcp-server enables centralized, multi-user deployments of Terraform via a streamable-HTTP transport. It supports two modes — stateful (default, per-session caching of Terraform API clients) and stateless (each request independent, required for multiple replicas behind a load balancer). The server authenticates via bearer tokens for HCP Terraform or Terraform Enterprise. All three CVEs affect the streamable-HTTP transport only; stdio (local single-user) mode is unaffected. Affected versions: 0.2.1 through 1.0.0.

**CVE-2026-16498 (CVSS 3.1: 10.0, Critical)** — Cross-tenant credential reuse in stateless streamable-HTTP mode. The underlying MCP library does not assign unique session identifiers to requests in stateless mode, and the server's per-session credential cache relies on those absent IDs. Consequently, one user's Terraform token is applied to subsequent users' requests regardless of the credentials they supply. This means User A's token executes tool calls (listing organizations, workspaces, variables, running operations) as User B. CISA SSVC: exploitation none, automatable yes, technical impact total. Availability impact is low (the vulnerability primarily affects confidentiality and integrity).

**CVE-2026-16496 (CVSS 3.1: 8.9, High)** — Authorization bypass (CWE-384 Session Fixation) in stateful streamable-HTTP mode. The per-session Terraform client cache uses the MCP session ID as its sole lookup key without binding the cached client to the token that created it. A remote attacker who obtains another user's MCP session ID can supply it in their own requests and inherit the victim's cached credentials, gaining access to the victim's Terraform organizations, workspaces, variables, and other resources within the scope of that token's permissions. Requires no authentication to initiate but demands high attack complexity (obtaining another user's session ID). Reported by Juan Pablo Martinez Kuhn (Coinspect).

**CVE-2026-14869 (CVSS 3.1: 8.6, High)** — Server-Side Request Forgery (CWE-918) in the streamable-HTTP transport layer. Request middleware rejected a client-supplied Terraform address when provided as an HTTP header, but did not apply the same check when the same value was supplied as an HTTP query parameter. An unauthenticated attacker can redirect the server's Terraform API requests — including the server-side bearer token configured for server-authenticated deployments — to an attacker-controlled endpoint, exfiltrating the token. Found internally by HashiCorp. CISA SSVC: automatable.

## Django (4 CVEs, Fixed in 6.0.8 / 5.2.17, August 4, 2026)

**CVE-2026-15307 (CVSS 4.0: 8.7 / CVSS 3.1: 8.8, High)** — Server-side file write and request forgery via GeoDjango spatial lookups (CWE-73, CWE-918). The right-hand-side value in a spatial lookup is optimistically parsed by GDALRaster. A dict or its JSON-string representation is opened in write mode by file-backed GDAL drivers, enabling attacker-chosen file writes. Non-dict strings trigger outbound network requests through GDAL virtual filesystem handlers (SSRF). Critically, the Django admin changelist permits filtering via ModelAdmin.lookup_allowed(), meaning any staff user with view permission on a model containing a spatial field (GeometryField or RasterField) can trigger the vulnerability through the admin interface. Writing a file to a location later imported by the application can result in remote code execution. Fix: dict values and invalid GEOSGeometry strings are now rejected by spatial lookups (backward-incompatible). Reported by Bence Nagy, localhost-detect, and kimchunbok_.

**CVE-2026-15920 (CVSS 3.1: 6.1, Medium)** — Stored cross-site scripting (CWE-83) via URLField values in the Django admin. The admin's display_for_field() function renders URLField values as clickable links on changelist and read-only admin pages without URL validation. An attacker who can store a URLField value with a dangerous scheme (such as javascript:) can create an XSS vector against other admin users viewing the data. Fix: URLField values are now validated via URLValidator before rendering; non-http(s) schemes render as plain text. Reported by Egor Saltykov.

**CVE-2026-15830 (CVSS 4.0: 6.9 / CVSS 3.1: 5.3, Medium)** — Denial of service via deeply nested GEOMETRYCOLLECTION objects (CWE-674 Uncontrolled Recursion). Processing deeply nested GEOMETRYCOLLECTION WKT/WKB inputs triggers unbounded recursion and a segmentation fault in the GEOS library. Spatial field lookups, GeometryField form fields, and GEOSGeometry parsing are all affected. Fix: maximum depth limits of 198 collections enforced. CISA SSVC: automatable. Reported by Andrew MacPherson and kimchunbok_.

**CVE-2026-15337 (CVSS 4.0: 6.9 / CVSS 3.1: 5.3, Medium)** — Denial of service via memory consumption (CWE-789) in check_for_language(). When many distinct, very long language codes are supplied, each is retained as a key in an in-memory cache, consuming process memory. The attack surface goes through django.views.i18n.set_language() (not routed by default) via POST data. Mitigating factors: DATA_UPLOAD_MAX_MEMORY_SIZE caps request data, and the cache has a fixed maximum entry limit. Fix: language codes longer than 500 characters are now rejected before cached lookup. Reported by Jaeyoung Jang.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1078 Valid Accounts
- T1505 Server Software Component
- T1574 Hijack Execution Flow
- T1555 Credentials from Password Stores
- T1528 Steal Application Access Token
- T1087 Account Discovery
- T1069 Permission Groups Discovery
- T1550 Use Alternate Authentication Material
- T1119 Automated Collection
- T1090 Proxy
- T1048 Exfiltration Over Alternative Protocol

## Sources

- [The Hacker News — Veeam, Terraform MCP, Django Patch Roundup](https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html)
- [Veeam KB4893 — Critical Vulnerabilities in Veeam Service Provider Console](https://www.veeam.com/kb4893)
- [HCSEC-2026-23 — Multiple Vulnerabilities in HashiCorp Terraform MCP Server](https://discuss.hashicorp.com/t/hcsec-2026-23-multiple-vulnerabilities-impacting-hashicorp-terraform-mcp-server/77606)
- [Django 6.0.8 / 5.2.17 Security Release](https://www.djangoproject.com/weblog/2026/aug/04/security-releases/)
- [NVD — CVE-2026-58073 (Veeam VSPC Agent Impersonation, CVSS 9.5)](https://nvd.nist.gov/vuln/detail/CVE-2026-58073)
- [NVD — CVE-2026-16498 (Terraform MCP Cross-Tenant Credential Reuse, CVSS 10.0)](https://nvd.nist.gov/vuln/detail/CVE-2026-16498)
- [NVD — CVE-2026-15307 (Django GeoDjango File Write/RCE, CVSS 8.8)](https://nvd.nist.gov/vuln/detail/CVE-2026-15307)
- [NVD — CVE-2026-16496 (Terraform MCP Session Cache Bypass, CVSS 8.9)](https://nvd.nist.gov/vuln/detail/CVE-2026-16496)
- [NVD — CVE-2026-14869 (Terraform MCP SSRF, CVSS 8.6)](https://nvd.nist.gov/vuln/detail/CVE-2026-14869)
- [NVD — CVE-2026-58072 (Veeam VSPC Arbitrary File Write, CVSS 9.0)](https://nvd.nist.gov/vuln/detail/CVE-2026-58072)
- [NVD — CVE-2026-15920 (Django Stored XSS, CVSS 6.1)](https://nvd.nist.gov/vuln/detail/CVE-2026-15920)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1891
