CVE-2026-72530
Published Aug 19, 2026
Last updated 23 days ago
AI description
CVE-2026-72530 is a code injection vulnerability affecting TrueConf Server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier. This flaw allows a remote, unauthorized attacker with network access via port 4307/TCP to utilize a specially crafted script. The vulnerability enables the attacker to break out of the isolated environment within the TrueConf server and subsequently execute arbitrary code on the host system. This CVE is often discussed in conjunction with CVE-2026-72529, which is a missing authentication vulnerability that can allow an unauthenticated remote attacker to execute an arbitrary script. CISA has added CVE-2026-72530 to its Known Exploited Vulnerabilities catalog, indicating evidence of active exploitation.
- Description
- A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
- Source
- vulnerability@kaspersky.com
- NVD status
- Analyzed
- Products
- trueconf_server
CVSS 4.0
- Type
- Secondary
- Base score
- 9.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Secondary
- Base score
- 9
- Impact score
- 6
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- TrueConf Server Code Injection Vulnerability
- Exploit added on
- Aug 20, 2026
- Exploit action due
- Sep 3, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- vulnerability@kaspersky.com
- CWE-94
- Hype score
- Not currently trending
🚨 TrueConf Server RCE (CVE-2026-72529/CVE-2026-72530): exploited since July, CISA KEV Aug20, public PoC Aug26, PhantomCore delivered via fake client update. #TrueConf #RCE #CISAKEV ➡️ https://t.co/Y5V8luXEZz https://t.co/lhpToTSVMG
@leonov_av
4 Sept 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CISA added a #TrueConf code injection flaw (CVE-2026-72530) to its KEV catalog due to active exploitation. #VioletBridgeSecurity helps manage third-party vendor risk. Is your team monitoring? 🔒 https://t.co/m5OkFARIm1
@VioletBridgeSec
1 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added two TrueConf Server flaws to KEV on August 20: CVE-2026-72529, missing authentication for a critical function, and CVE-2026-72530, code injection. Self-hosted conferencing servers are a recurring pattern. Internet-facing by requirement, deployed once, patched rarely,
@Frankly_Alen
31 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: CVE-2026-72530 in TrueConf Server allows remote code execution via port 4307/TCP. Attackers can break isolation & execute arbitrary code. Added to CISA KEV—patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/BIWOWrKrLb
@DFIR_Lab
30 Aug 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA KEVed TrueConf Server CVE-2026-72529 (due Aug 23). Unauth TCP 4307 script exec. ITW chain with CVE-2026-72530 sandbox breakout (PhantomCore). Patch 5.3.9 / 5.4.9 / 5.5.5. Check 4307 exposure; hunt IoCs. https://t.co/U7wQ8Im6O5 #CISA
@snypet86
24 Aug 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited vulnerabilities CVE-2026-72529 and CVE-2026-72530 pose severe risks to federal systems. More details: https://t.co/ExuHpfQxT5 https://t.co/rWDqEhCMAW
@Cybernews
24 Aug 2026
1291 Impressions
4 Retweets
12 Likes
3 Bookmarks
1 Reply
0 Quotes
⚠️⚠️ CVE-2026-72529 (CVSS 9.8) + CVE-2026-72530 (CVSS 9.0): Unauthenticated RCE in TrueConf Server 🔗FOFA Link: https://t.co/feqKNKMbsN 🎯2.9K+ Results are found on https://t.co/NBEEGu7ePJ in the past year. FOFA Query: app="TrueConf-VCS" 🔖Refer: https://t.co/i49AVi
@fofabot
24 Aug 2026
2630 Impressions
16 Retweets
37 Likes
12 Bookmarks
0 Replies
0 Quotes
🛡️ CYBER BULLETIN | 2026/08/23 🚨 1. CISA flags actively exploited TrueConf Server flaws Two critical vulnerabilities in the self-hosted video platform (CVE-2026-72529 and CVE-2026-72530) landed in CISA’s KEV catalog. Attackers with network access can run arbitrary code
@FrontieraTechIT
23 Aug 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
TrueConf Server CVE-2026-72529 is unauthenticated script execution over TCP 4307. CVE-2026-72530 then escapes the sandbox onto the host. Both are exploited this week. June builds 5.3.9 / 5.4.9 / 5.5.5 close the chain. Patch now and keep 4307 off the internet.
@mazz_andrea
22 Aug 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
IT/security teams running self-hosted TrueConf Server: patch now. CISA added CVE-2026-72529 and CVE-2026-72530 to KEV after active exploitation. Federal deadline: Sept. 3. Is TCP 4307 exposed? https://t.co/kJdtqYwCRA
@Techsico_IT
22 Aug 2026
25 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Your on-prem video server just became the malware. Head Mare chained two unauth bugs in TrueConf Server — CVE-2026-72529 (RCE) + CVE-2026-72530 (sandbox escape) — to SYSTEM, then swapped the client installer every employee downloads. CISA KEV'd both Aug 20. 🧵 1/5
@zerohuntai
22 Aug 2026
33 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🔐🚨 TrueConf Server — CISA KEV, CVSS 9.8 RCE CVE-2026-72530: Unauthenticated code injection via port 4307/TCP → Active exploitation by Head Mare group → https://t.co/Tzaa5nI5Rp #cybersecurity #infosec #TrueConf #CISA #KEV #RCE #PatchNow #ThreatIntel
@ThreatAft
22 Aug 2026
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Attackers are chaining two critical TrueConf Server vulnerabilities to gain complete system control. CVE-2026-72529 bypasses authentication while CVE-2026-72530 enables code injection, creating a pathway from initial access to lateral movement. Runtime segmentation helps contain
@aviatrixtrc
21 Aug 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
DEEP DIVE — CVE-2026-72529: unauthenticated script execution in TrueConf Server over TCP/4307 (CVSS 9.8), chained with CVE-2026-72530 to reach SYSTEM. KEV-listed with a 3-day deadline. The patch shipped in June, two months before the CVE ID was published. https://t.co/7yEhqCcwU
@DailyCVEBrief
21 Aug 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Warning: Critical Missing Authentication and Code Injection vulnerabilities in #TrueConfServer. CVE-2026-72529 CVSS: 9.3 / CVE-2026-72530 CVSS: 9.5. This actively exploited vulnerability chain results in remote code execution #RCE! Time to #Patch #Patch #Patch
@CCBalert
21 Aug 2026
214 Impressions
1 Retweet
0 Likes
1 Bookmark
0 Replies
0 Quotes
CISA Adds TrueConf Server Vulnerabilities to KEV Catalog — CISA has added CVE-2026-72529 and CVE-2026-72530 affecting TrueConf Server to its Known… https://t.co/k1xOHKgqbp #Cybersecurity #SecOps #VulnerabilityManagement
@VettedSecOps
21 Aug 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
TrueConf shows how a trusted update path can become an attack path: CVE-2026-72529 → CVE-2026-72530 → SYSTEM → web shell → client installer → endpoints Server compromise was observed. Which endpoints actually executed the payload still requires validation. #TrueConf
@vufaysecurity
21 Aug 2026
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA gives federal agencies until September 3 to patch two critical TrueConf Server flaws now under active exploitation. CVE-2026-72529 enables unauthenticated RCE over port 4307; CVE-2026-72530 escapes the sandbox. Kaspersky ties the activity to Head Mare, active since July.
@XavierRiveraX
21 Aug 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-72530: TrueConf Server Code Injection Actively Exploited — Detection a… "On August 20, 2026, CISA added CVE-2026-72530 — a code injection vulnerability in…" 🔗 https://t.co/ffQDC3NyHv #CyberSecurity #ThreatIntel #cve202672530 #critical #
@SecurityAr58409
21 Aug 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA adds two critical TrueConf Server flaws to the KEV catalog. CVE-2026-72529 (CVSS 9.8) allows unauthenticated remote script execution via missing auth. CVE-2026-72530 (CVSS 9.0) enables code injection that escapes the sandbox to run arbitrary code on the host over TCP 4307.
@WorldCyberNewsX
21 Aug 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに、TrueConfのCVE-2026-72529(認証欠如)とCVE-2026-72530(コードインジェクション)を追加。対処期限は72529が3日後の8/23、725
@__kokumoto
20 Aug 2026
593 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now. #TrueConf #CVE #ExploitedInTheWild #PhantomCore #HeadMare #InfoSec #PatchNow https://t.co/3XCq8xeN5J
@Daily_CyberSec
20 Aug 2026
399 Impressions
1 Retweet
0 Likes
1 Bookmark
0 Replies
0 Quotes
🛡️ Alerta de Seguridad: Inyección de Código Remota en TrueConf Server vía Puerto 4307/TCP (CVE-2026-72530) Vulnerabilidad crítica (CVSS 9.0) en TrueConf Server permite RCE remoto sin autenticación a través del puerto 4307/TCP mediante script malicioso que rompe el ento
@CiberPlanetaOrg
20 Aug 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ CVE-2026-72530: Vulnerabilidad Crítica de Inyección de Código en TrueConf Server Explotada Activamente Análisis técnico del CVE-2026-72530 en TrueConf Server: inyección de código remota sin autenticación, CVSS 9.0, explotación activa confirmada por CISA.
@CiberPlanetaOrg
20 Aug 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️We added TrueConf Server vulnerabilities CVE-2026-72529 & CVE-2026-72530 to our Known Exploited Vulnerabilities Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/dzrodjLszP
@CISACyber
20 Aug 2026
7589 Impressions
11 Retweets
31 Likes
4 Bookmarks
0 Replies
1 Quote
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*",
"matchCriteriaId": "223F39D3-6C0B-449C-BBC4-22E9FD1069B0",
"versionEndExcluding": "5.3.9.10013",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*",
"matchCriteriaId": "651E4015-13F5-467A-B994-8CD8CF096F2B",
"versionEndExcluding": "5.3.9.10015",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*",
"matchCriteriaId": "92B109B3-71FC-46C8-9790-602F6E82A1B4",
"versionEndExcluding": "5.4.9.10072",
"versionStartIncluding": "5.4.0.12689",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*",
"matchCriteriaId": "991CB573-4063-4F9F-980C-73049E0D86BF",
"versionEndExcluding": "5.4.9.10019",
"versionStartIncluding": "5.4.0.12700",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:windows:*:*",
"matchCriteriaId": "BA7EE78E-8CC5-4F6E-8BE2-485C61334D3C",
"versionEndExcluding": "5.5.5.10010",
"versionStartIncluding": "5.5.0.13826",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:trueconf:trueconf_server:*:*:*:*:*:linux_kernel:*:*",
"matchCriteriaId": "1B3BF976-3656-4152-A255-ABA311510C7C",
"versionEndExcluding": "5.5.5.10009",
"versionStartIncluding": "5.5.0.13828",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]