Critical Flaws Patched in Veeam, HashiCorp Terraform MCP, and Django - Update Now
HashiCorp, Veeam, and the Django Software Foundation have released patches addressing 11 security vulnerabilities across their respective products, including Terraform MCP Server, Veeam Service Provider Console, and the Django web framework. Among these, two flaws stand out for their severity and potential business impact.
The most critical issue affects HashiCorp's Terraform MCP Server, where a cross-tenant flaw allows one user's Terraform token to be reused by a different user afterward. This could let unauthorised parties access infrastructure or data belonging to another tenant, a serious concern for managed service providers and businesses using shared cloud tooling. Separately, an unauthenticated vulnerability in Veeam's Service Provider Console, rated 9.5 in severity, can expose the credentials of a managed backup agent without requiring any login, potentially giving attackers a foothold into backup systems.
While full technical details remain limited, the involvement of widely-used platforms like Veeam and Terraform means many Australian businesses relying on managed service providers or cloud infrastructure tooling could be indirectly affected. Businesses should check with their IT provider or vendor to confirm whether the affected products are in use and that patches have been applied promptly.