HashiCorp security patch release for CVE-2026-16498
Security Patch Release
Summary
Hide ▲
Show ▼
HashiCorp released Terraform MCP Server 1.1.0 to fix three Streamable HTTP flaws, including CVE-2026-16498 token reuse and CVE-2026-14869 SSRF, that could affect shared deployments. The bugs apply to multi-user HTTP mode rather than stdio mode, and operators are told to update to 1.1.0 or later. No active exploitation or public proof-of-concept was reported, and none of the CVEs was in CISA's KEV catalog as of August 5, 2026.
Related Happenings
N-able N-central servers hit by network compromise
Incident
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
N-able N-central servers hit by network compromise
IncidentAbout this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.
Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
Campaign
H score47
First: 31.07.2026 18:00
Last: 31.07.2026 18:00
Sources 1
About this happening:
The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...
Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
CampaignAbout this happening: The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...
F5 security patch release for CVE-2026-42530
Security Patch Release
H score39
First: 18.06.2026 20:32
Last: 18.06.2026 20:32
Sources 1
About this happening:
F5 released security updates for NGINX Open Source after finding two critical vulnerabilities that could lead to remote code execution on affected systems. The pat...
F5 security patch release for CVE-2026-42530
Security Patch ReleaseAbout this happening: F5 released security updates for NGINX Open Source after finding two critical vulnerabilities that could lead to remote code execution on affected systems. The pat...
LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch Release
H score42
First: 15.06.2026 19:39
Last: 15.06.2026 19:39
Sources 1
About this happening:
BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...
LiteLLM v1.83.14-stable security fix release (multiple vulnerabilities)
Security Patch ReleaseAbout this happening: BerriAI shipped LiteLLM v1.83.14-stable to close a three-CVE chain that could let a low-privilege proxy user reach full admin and run code on the server. The u...
LiteLLM endpoint-hardening patch release (CVE-2026-42271)
Security Patch Release
H score59
First: 09.06.2026 09:26
Last: 09.06.2026 09:26
Sources 1
About this happening:
BerriAI released LiteLLM 1.83.7, hardening access to the vulnerable MCP test endpoints that accepted full server configurations. The update now requires the PROXY_ADMIN*...
LiteLLM endpoint-hardening patch release (CVE-2026-42271)
Security Patch ReleaseAbout this happening: BerriAI released LiteLLM 1.83.7, hardening access to the vulnerable MCP test endpoints that accepted full server configurations. The update now requires the PROXY_ADMIN*...
Timeline
-
05.08.2026 17:27 2 articles · 2h ago
HashiCorp releases Terraform MCP Server 1.1.0
Mitigation Patch UpdateHashiCorp released Terraform MCP Server 1.1.0 as the fixed build for the Streamable HTTP transport flaws affecting multi-user, centralized deployments.
Show sources
- Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug — thehackernews.com — 05.08.2026 17:27
- Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug — thehackernews.com — 05.08.2026 17:27
-
05.08.2026 17:27 1 articles · 2h ago
HashiCorp discloses three Streamable HTTP flaws in Terraform MCP Server
Initial DisclosureHashiCorp disclosed three related Terraform MCP Server flaws in Streamable HTTP mode: CVE-2026-16498 cross-tenant credential reuse in stateless HTTP mode, CVE-2026-16496 session-isolation failure in stateful mode, and CVE-2026-14869 server-side request forgery.
Show sources
- Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug — thehackernews.com — 05.08.2026 17:27
-
05.08.2026 17:27 1 articles · 2h ago
No active exploitation is reported for Terraform MCP Server flaws
Untyped PhaseAs of August 5, 2026, the HashiCorp advisory said the Terraform MCP Server flaws were not under active exploitation, no public proof-of-concept had surfaced, and operators were told to update to Terraform MCP Server 1.1.0 or later.
Show sources
- Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug — thehackernews.com — 05.08.2026 17:27