U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
ID: 7ae5e05f-1122-5b8c-8a17-bcbd7ccf5ce8
STIX ID: report--7ae5e05f-1122-5b8c-8a17-bcbd7ccf5ce8
Feed Name: Security Affairs
CISA added two critical TrueConf Server vulnerabilities (CVE-2026-72529: missing authentication leading to remote code execution; CVE-2026-72530: code injection/sandbox escape) to its Known Exploited Vulnerabilities catalog; both allow unauthenticated attackers with network access to TCP port 4307 to execute arbitrary code on affected TrueConf Server 5.3.x–5.5.x installations, were discovered by Vyacheslav Kopeytsev of Kaspersky ICS CERT, and federal agencies are required to remediate by specified August/September 2026 deadlines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
