When a security issue is revealed mid-sprint, the project manager should consult with both the product owner and the project team. The product owner is responsible for prioritizing the backlog and ensuring that the most valuable features are worked on, while the team will help assess the technical implications of addressing the security issue. The product owner needs to understand the impact of the security issue on the product's value and determine if it needs to be prioritized over other work in the sprint. The project team should help evaluate the effort required to address the issue and ensure that the solution is feasible within the sprint's capacity. By collaborating with both the product owner and the team, the project manager can make an informed decision on whether to adjust the sprint plan, reprioritize the backlog, or take necessary actions to address the vulnerability. This ensures that the security issue is resolved without jeopardizing the overall sprint goals.