logo

U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog

ID: 7ae5e05f-1122-5b8c-8a17-bcbd7ccf5ce8

STIX ID: report--7ae5e05f-1122-5b8c-8a17-bcbd7ccf5ce8

Feed Name: Security Affairs

Threat Score
80/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: Pierluigi Paganini

...
...

CISA added two critical TrueConf Server vulnerabilities (CVE-2026-72529: missing authentication leading to remote code execution; CVE-2026-72530: code injection/sandbox escape) to its Known Exploited Vulnerabilities catalog; both allow unauthenticated attackers with network access to TCP port 4307 to execute arbitrary code on affected TrueConf Server 5.3.x–5.5.x installations, were discovered by Vyacheslav Kopeytsev of Kaspersky ICS CERT, and federal agencies are required to remediate by specified August/September 2026 deadlines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.