CISA warns of actively exploited TrueConf vulnerabilities.
ID: 6d37c859-d974-56ea-884f-5e3d9a0c69b9
STIX ID: report--6d37c859-d974-56ea-884f-5e3d9a0c69b9
Feed Name: The CyberWire
Threat Score
CISA warns that TrueConf Server has two actively exploited vulnerabilities (CVE-2026-72529 allowing remote script execution and CVE-2026-72530 enabling escape from isolated environments), a supply-chain attack injected malicious build-time code into popular Rust crates (arrayref and append-only-vec) that downloads and executes payloads during compilation, and AI data company Alation confirmed a cyberattack under investigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
