U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
CISA added two exploited TrueConf Server flaws (CVE-2026-72529, CVE-2026-72530) to its KEV catalog with federal patch deadlines.
CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-72529 (CVSS 9.3), a missing-authentication remote code execution flaw reachable on TCP port 4307, and CVE-2026-72530 (CVSS 9.5), a sandbox escape allowing code execution on the underlying host. Both flaws affect TrueConf Server versions 5.3.x through 5.5.5 and earlier, and were discovered by Vyacheslav Kopeytsev of Kaspersky ICS CERT. Under BOD 22-01, federal civilian agencies must patch CVE-2026-72529 by August 23, 2026, and CVE-2026-72530 by September 2, 2026.
- CVE-2026-72529 (CVSS 9.3) allows unauthenticated RCE via an undocumented function on TCP port 4307.
- CVE-2026-72530 (CVSS 9.5) is a sandbox escape enabling arbitrary code execution on the host.
- Flaws affect TrueConf Server 5.3.x through 5.5.5 and earlier on-premises deployments.
- Federal agencies face patch deadlines of August 23 and September 2, 2026 under BOD 22-01.
- Compromised servers could serve as entry points into affected networks.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-72530 +1 in the same advisory: …72529 | Code Injection Sandbox Escape in TrueConf Server Allows Host RCE via TCP 4307 TrueConf Server contains a code injection flaw (CWE-94) that allows a remote, unauthenticated attacker with network access to TCP port 4307 to send a specially crafted script that breaks out of the server's isolated environment and executes arbitrary code on the underlying host. The flaw affects TrueConf Server 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier releases. A successful attack yields full code execution on the host system, not just the conferencing application, although the critical CVSS 4.0 score of 9.5 includes high attack complexity and attack-requirements factors. Organizations running self-hosted TrueConf video conferencing servers, especially those with port 4307 exposed to untrusted networks, are in scope. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-20, a public PoC exists, and Kaspersky's Securelist reports the Head Mare threat actor has actively targeted TrueConf Server to deploy PhantomCore malware. Do: Upgrade TrueConf Server to a fixed release beyond the affected ranges (later than 5.5.5, per vendor instructions) as the primary remediation. Until patched, restrict access to TCP port 4307 so it is not reachable from untrusted networks and review server logs for signs of exploitation. U.S. federal agencies must apply these mitigations in accordance with BOD 26-04 following the KEV listing (added 2026-08-20), or discontinue use of the product if mitigations are unavailable. | 9.5 group max | 2% | KEV PoC |
| moderate≈ low thousands of self-hosted server deployments; exact install base not published |
Full article409 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2026-72529 (CVSS score of 9.3) TrueConf Server Missing Authentication for Critical Function Vulnerability
- CVE-2026-72530 (CVSS score of 9.5) TrueConf Server Code Injection Vulnerability
TrueConf Server is an on-premises video conferencing and unified communications platform developed by TrueConf. Organizations can deploy it on their own infrastructure to provide secure video meetings, voice calls, messaging and collaboration without relying entirely on a cloud service.
It is typically used by businesses, government organizations and other institutions that want to keep communications and related data under their own control.
CVE-2026-72529 is a remote code execution vulnerability in TrueConf Server that allows an unauthenticated remote attacker with network access to TCP port 4307 to execute arbitrary scripts by calling an undocumented function.
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions. An attacker who can reach the vulnerable service could potentially compromise the server and use it as an entry point into the affected network.
CVE-2026-72530 is a sandbox escape vulnerability in TrueConf Server that allows an unauthenticated remote attacker with network access to TCP port 4307 to break out of an isolated environment and execute arbitrary code on the underlying host.
The flaw affects TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and earlier versions. By sending a specially crafted script, an attacker could escape the restricted environment and gain code execution on the host system, potentially leading to a full server compromise.
In the context of CVE-2026-72529 and CVE-2026-72530, the concern is that vulnerable TrueConf Server installations exposed on TCP port 4307 could provide attackers with a path to execute code on the server.
Vyacheslav Kopeytsev from Kaspersky ICS CERT discovered both vulnerabilities.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the flaw CVE-2026-72529 by August 23, 2026, and CVE-2026-72530 by September 2nd.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/197602/security/u-s-cisa-adds-trueconf-server-flaws-to-its-known-exploited-vulnerabilities-catalog.html