Unauthenticated RCE in TrueConf Server via undocumented function on port 4307
CISA: TrueConf Server Missing Authentication for Critical Function Vulnerability
CVSS 4.0
9.3critical
EPSS
2%p74
Published
()
KEV added
AI analysis
CVE-2026-72529 is a missing-authentication vulnerability (CWE-306) in TrueConf Server that lets a remote, unauthenticated attacker reach an undocumented function over TCP port 4307 and execute an arbitrary script on the server. It is triggered simply by sending crafted requests to that port on an affected build, with no credentials or user interaction required. Successful exploitation yields code execution with high impact on the server's confidentiality, integrity, and availability (CVSS 4.0 base score 9.3). Any organization running TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, or earlier versions is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-20, and a public Kaspersky (Securelist) report documents the Head Mare threat actor targeting TrueConf Server with the PhantomCore backdoor, confirming in-the-wild exploitation; EPSS currently estimates a 1.6% chance of exploitation in the next 30 days.
What to do: Upgrade all TrueConf Server deployments to a release newer than 5.5.5 (the highest listed affected version) per vendor instructions, and until patched restrict access to TCP port 4307 from untrusted networks and confirm the server is not internet-exposed. Federal agencies must apply mitigations consistent with CISA BOD 26-04 or discontinue use of the product. Hunt for compromise indicators on affected servers, since Head Mare has been observed exploiting this flaw to deploy the PhantomCore backdoor.
Affected
TrueConf Server
5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and all earlier versions
Estimated exposure
moderateseveral thousand to tens of thousands of on-premises server deployments (exact count unknown) — No public install counts or internet-exposure scan data were provided, so the estimate is based on TrueConf Server's deployment pattern as a self-hosted enterprise videoconferencing product concentrated in the Russian/CIS market rather…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
CISA Known Exploited Vulnerability
Affected
TrueConf Server
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA added two exploited TrueConf Server flaws (CVE-2026-72529, CVE-2026-72530) to its KEV catalog with federal patch deadlines.
CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-72529 (CVSS 9.3), a missing-authentication remote code execution flaw reachable on TCP port 4307, and CVE-2026-72530 (CVSS 9.5), a sandbox escape allowing code execution on the underlying host. Both flaws affect TrueConf Server versions 5.3.x through 5.5.5 and earlier, and were discovered by Vyacheslav Kopeytsev of Kaspersky ICS CERT. Under BOD 22-01, federal civilian agencies must patch CVE-2026-72529 by August 23, 2026, and CVE-2026-72530 by September 2, 2026.