Vulnerabilities
17 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-72530 +1 in the same advisory: …72529 | Code Injection Sandbox Escape in TrueConf Server Allows Host RCE via TCP 4307 TrueConf Server contains a code injection flaw (CWE-94) that allows a remote, unauthenticated attacker with network access to TCP port 4307 to send a specially crafted script that breaks out of the server's isolated environment and executes arbitrary code on the underlying host. The flaw affects TrueConf Server 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier releases. A successful attack yields full code execution on the host system, not just the conferencing application, although the critical CVSS 4.0 score of 9.5 includes high attack complexity and attack-requirements factors. Organizations running self-hosted TrueConf video conferencing servers, especially those with port 4307 exposed to untrusted networks, are in scope. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-20, a public PoC exists, and Kaspersky's Securelist reports the Head Mare threat actor has actively targeted TrueConf Server to deploy PhantomCore malware. Do: Upgrade TrueConf Server to a fixed release beyond the affected ranges (later than 5.5.5, per vendor instructions) as the primary remediation. Until patched, restrict access to TCP port 4307 so it is not reachable from untrusted networks and review server logs for signs of exploitation. U.S. federal agencies must apply these mitigations in accordance with BOD 26-04 following the KEV listing (added 2026-08-20), or discontinue use of the product if mitigations are unavailable. | 9.5 group max | 2% | KEV PoC |
| moderate≈ low thousands of self-hosted server deployments; exact install base not published | |
| CVE-2026-3502 | Arbitrary Code Execution via Unverified Updates in TrueConf Client CVE-2026-3502 is a download-of-code-without-integrity-check flaw (CWE-494) in TrueConf Client: the application downloads update code and applies it without verifying its integrity. An attacker who can influence the update delivery path can substitute a tampered update payload, and if that payload is executed or installed by the updater, arbitrary code runs in the context of the updating process or the user. The flaw is rated 7.8 (high) on CVSS 3.1 and affects TrueConf Client deployments, which are concentrated in enterprise and government video conferencing environments. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-02, and public reporting describes it as a zero-day used against Southeast Asian government networks by actors attributed to Chinese hackers, with CISA giving agencies roughly two weeks to remediate. Ransomware use is unknown, and no public proof-of-concept is known beyond the observed attacks; EPSS estimates a 5.7% chance of exploitation within 30 days (93rd percentile). Do: Apply the vendor's fix or mitigations per CISA's KEV required action and BOD 22-01; federal agencies had roughly two weeks from the 2026-04-02 KEV listing to remediate or discontinue use. Until patched, restrict and monitor the network path between TrueConf Clients and their update source, and check endpoints for unexpected update or installer activity and newly created processes. Identify which TrueConf Client versions are in use and confirm affected and fixed versions against the vendor's advisory, since the source data does not specify version ranges. | 7.8 | 6% | KEV |
| moderate~10k-100k endpoints (deployment-pattern estimate; no public install or scan counts available) | |
| CVE-2025-66824 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.108 A Stored Cross-Site Scripting (XSS) vulnerability exists in the Meeting location field of the Create/Edit Conference functionality in TrueConf Server v5.5.2.10813. The injected payload is stored via the meeting_room parameter and executed when users visit the Conference Info page, allowing attackers to achieve full Account Takeover (ATO). This issue is caused by improper sanitization of user-supplied input in the meeting_room field. NVD description · AI analysis pending | 8.7 group max | <1% | PoC |
| — | |
| CVE-2025-66835 | TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the user's context. TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the user's context. NVD description · AI analysis pending | 7.1 | <1% | PoC |
| — | |
| CVE-2022-46764 +1 in the same advisory: …46763 | A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL comm A SQL injection issue in the web API in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows remote unauthenticated attackers to execute arbitrary SQL commands, ultimately leading to remote code execution. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2017-20120 | A vulnerability classified as problematic was found in TrueConf Server 4.3.7. A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2017-20119 | A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argument redirect_url leads to open redirect. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 6.1 group max | <1% | PoC |
| — |