CVE-2026-72529

Published Aug 19, 2026

Last updated 2 months ago

Exploit knownCVSS critical 9.3
Zero-day
Supply chain
TrueConf Server

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-72529 is a missing-authentication vulnerability found in TrueConf Server. This flaw allows an unauthenticated remote attacker, with network access to the affected service via TCP port 4307, to execute an arbitrary script. This vulnerability has been observed in active exploitation and is often discussed alongside CVE-2026-72530, a related code injection vulnerability that permits attackers to break out of an isolated environment and execute arbitrary code on the host system. TrueConf has released patched versions (5.3.9, 5.4.9, and 5.5.5) to address this issue.

Description
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Source
vulnerability@kaspersky.com
NVD status
Analyzed
Products
trueconf_server

Risk scores

CVSS 4.0

Type
Secondary
Base score
9.3
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
TrueConf Server Missing Authentication for Critical Function Vulnerability
Exploit added on
Aug 20, 2026
Exploit action due
Aug 23, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

vulnerability@kaspersky.com
CWE-306

Social media

Hype score
Not currently trending
  1. 🚨 TrueConf Server RCE (CVE-2026-72529/CVE-2026-72530): exploited since July, CISA KEV Aug20, public PoC Aug26, PhantomCore delivered via fake client update. #TrueConf #RCE #CISAKEV ➡️ https://t.co/Y5V8luXEZz https://t.co/lhpToTSVMG

    @leonov_av

    4 Sept 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CISA added two TrueConf Server flaws to KEV on August 20: CVE-2026-72529, missing authentication for a critical function, and CVE-2026-72530, code injection. Self-hosted conferencing servers are a recurring pattern. Internet-facing by requirement, deployed once, patched rarely,

    @Frankly_Alen

    31 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 CRITICAL: CVE-2026-72529 in TrueConf Server - Missing authentication allows remote code execution via port 4307/TCP. Added to CISA KEV. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/skSZHx2yGM

    @DFIR_Lab

    30 Aug 2026

    39 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🔴 TrueConf Server, Missing Authentication, #CVE-2026-72529 (Critical) -DC-Aug2026-1981 https://t.co/hLa1fIwRsk

    @dailycve

    28 Aug 2026

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CISA KEVed TrueConf Server CVE-2026-72529 (due Aug 23). Unauth TCP 4307 script exec. ITW chain with CVE-2026-72530 sandbox breakout (PhantomCore). Patch 5.3.9 / 5.4.9 / 5.5.5. Check 4307 exposure; hunt IoCs. https://t.co/U7wQ8Im6O5 #CISA

    @snypet86

    24 Aug 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Actively exploited vulnerabilities CVE-2026-72529 and CVE-2026-72530 pose severe risks to federal systems. More details: https://t.co/ExuHpfQxT5 https://t.co/rWDqEhCMAW

    @Cybernews

    24 Aug 2026

    1291 Impressions

    4 Retweets

    12 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  7. ⚠️⚠️ CVE-2026-72529 (CVSS 9.8) + CVE-2026-72530 (CVSS 9.0): Unauthenticated RCE in TrueConf Server 🔗FOFA Link: https://t.co/feqKNKMbsN 🎯2.9K+ Results are found on https://t.co/NBEEGu7ePJ in the past year. FOFA Query: app="TrueConf-VCS" 🔖Refer: https://t.co/i49AVi

    @fofabot

    24 Aug 2026

    2630 Impressions

    16 Retweets

    37 Likes

    12 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2026-72529 was just added to CISA's Known Exploited Vulnerabilities catalog. Affects: TrueConf Server. TrueConf Server Missing Authentication for Critical Function Vulnerability. If you run this, patch now, not later. https://t.co/JDFbFdZcai

    @intellibreach

    23 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🛡️ CYBER BULLETIN | 2026/08/23 🚨 1. CISA flags actively exploited TrueConf Server flaws Two critical vulnerabilities in the self-hosted video platform (CVE-2026-72529 and CVE-2026-72530) landed in CISA’s KEV catalog. Attackers with network access can run arbitrary code

    @FrontieraTechIT

    23 Aug 2026

    50 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  10. TrueConf Server CVE-2026-72529 is unauthenticated script execution over TCP 4307. CVE-2026-72530 then escapes the sandbox onto the host. Both are exploited this week. June builds 5.3.9 / 5.4.9 / 5.5.5 close the chain. Patch now and keep 4307 off the internet.

    @mazz_andrea

    22 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. IT/security teams running self-hosted TrueConf Server: patch now. CISA added CVE-2026-72529 and CVE-2026-72530 to KEV after active exploitation. Federal deadline: Sept. 3. Is TCP 4307 exposed? https://t.co/kJdtqYwCRA

    @Techsico_IT

    22 Aug 2026

    25 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Your on-prem video server just became the malware. Head Mare chained two unauth bugs in TrueConf Server — CVE-2026-72529 (RCE) + CVE-2026-72530 (sandbox escape) — to SYSTEM, then swapped the client installer every employee downloads. CISA KEV'd both Aug 20. 🧵 1/5

    @zerohuntai

    22 Aug 2026

    33 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. 🚨 CVE-of-the-Day: CVE-2026-72529 — TrueConf Server unauthenticated RCE via missing auth on port 4307, actively exploited CVSS: 9.8 | EPSS: 0.3% Unauthenticated attackers with network access to TCP/4307 can invoke an undocumented critical function and execute arbitrary scri

    @YourDailyCVE

    21 Aug 2026

    27 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  14. Attackers are chaining two critical TrueConf Server vulnerabilities to gain complete system control. CVE-2026-72529 bypasses authentication while CVE-2026-72530 enables code injection, creating a pathway from initial access to lateral movement. Runtime segmentation helps contain

    @aviatrixtrc

    21 Aug 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. DEEP DIVE — CVE-2026-72529: unauthenticated script execution in TrueConf Server over TCP/4307 (CVSS 9.8), chained with CVE-2026-72530 to reach SYSTEM. KEV-listed with a 3-day deadline. The patch shipped in June, two months before the CVE ID was published. https://t.co/7yEhqCcwU

    @DailyCVEBrief

    21 Aug 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  16. Warning: Critical Missing Authentication and Code Injection vulnerabilities in #TrueConfServer. CVE-2026-72529 CVSS: 9.3 / CVE-2026-72530 CVSS: 9.5. This actively exploited vulnerability chain results in remote code execution #RCE! Time to #Patch #Patch #Patch

    @CCBalert

    21 Aug 2026

    214 Impressions

    1 Retweet

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  17. CISA Adds TrueConf Server Vulnerabilities to KEV Catalog — CISA has added CVE-2026-72529 and CVE-2026-72530 affecting TrueConf Server to its Known… https://t.co/k1xOHKgqbp #Cybersecurity #SecOps #VulnerabilityManagement

    @VettedSecOps

    21 Aug 2026

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. TrueConf shows how a trusted update path can become an attack path: CVE-2026-72529 → CVE-2026-72530 → SYSTEM → web shell → client installer → endpoints Server compromise was observed. Which endpoints actually executed the payload still requires validation. #TrueConf

    @vufaysecurity

    21 Aug 2026

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. CISA gives federal agencies until September 3 to patch two critical TrueConf Server flaws now under active exploitation. CVE-2026-72529 enables unauthenticated RCE over port 4307; CVE-2026-72530 escapes the sandbox. Kaspersky ties the activity to Head Mare, active since July.

    @XavierRiveraX

    21 Aug 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. 🔒 #CyberSecurity CVE-2026-72529: TrueConf Server Missing Authentication Flaw Under Active Exploi… "On August 20, 2026, CISA added CVE-2026-72529 — a…" 🔗 https://t.co/QrRA8xJ36h #CyberSecurity #ThreatIntel #cve202672529 #critical #cisakev

    @SecurityAr58409

    21 Aug 2026

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. CISA adds two critical TrueConf Server flaws to the KEV catalog. CVE-2026-72529 (CVSS 9.8) allows unauthenticated remote script execution via missing auth. CVE-2026-72530 (CVSS 9.0) enables code injection that escapes the sandbox to run arbitrary code on the host over TCP 4307.

    @WorldCyberNewsX

    21 Aug 2026

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに、TrueConfのCVE-2026-72529(認証欠如)とCVE-2026-72530(コードインジェクション)を追加。対処期限は72529が3日後の8/23、725

    @__kokumoto

    20 Aug 2026

    593 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 🛡️ Alerta de Seguridad: TrueConf Server - Autenticación Ausente en Función Crítica permite RCE sin credenciales (CVE-2026-72529) CVE-2026-72529 (CVSS 9.8): TrueConf Server permite RCE remoto sin autenticación vía puerto 4307/TCP. Parche obligatorio antes del 23/08/2026

    @CiberPlanetaOrg

    20 Aug 2026

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now. #TrueConf #CVE #ExploitedInTheWild #PhantomCore #HeadMare #InfoSec #PatchNow https://t.co/3XCq8xeN5J

    @Daily_CyberSec

    20 Aug 2026

    399 Impressions

    1 Retweet

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  25. 🛡️ CVE-2026-72529: Vulnerabilidad Crítica de Autenticación en TrueConf Server Explotada Activamente Análisis técnico del CVE-2026-72529 en TrueConf Server: fallo de autenticación crítico (CVSS 9.8) que permite ejecución remota de scripts arbitrarios. https://t.co/sfg7

    @CiberPlanetaOrg

    20 Aug 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. 🛡️We added TrueConf Server vulnerabilities CVE-2026-72529 & CVE-2026-72530 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/dzrodjLszP

    @CISACyber

    20 Aug 2026

    7589 Impressions

    11 Retweets

    31 Likes

    4 Bookmarks

    0 Replies

    1 Quote

  27. 🚨*CVE* CVE-2026-72529 A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could… https://t.co/IwEbESdU3k ----- Traducción: CVE-2026-72529 Un … https://t.co/bYtskK

    @infoflowcloud

    19 Aug 2026

    26 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations