CVE-2026-72529
published 2026-08-19CVE-2026-72529: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and…
PriorityP191critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-08-23
Exploited in the wild
EPSS
0.78%
53.0th percentile
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| trueconf | trueconf_server | < 5.3.9.10013 | 5.3.9.10013 |
| trueconf | trueconf_server | < 5.3.9.10015 | 5.3.9.10015 |
| trueconf | trueconf_server | >= * < 5.3 | 5.3 |
| trueconf | trueconf_server | >= 5.3 < 5.3.9 | 5.3.9 |
| trueconf | trueconf_server | >= 5.4 < 5.4.9 | 5.4.9 |
| trueconf | trueconf_server | >= 5.4.0.12689 < 5.4.9.10072 | 5.4.9.10072 |
| trueconf | trueconf_server | >= 5.4.0.12700 < 5.4.9.10019 | 5.4.9.10019 |
| trueconf | trueconf_server | >= 5.5 < 5.5.5 | 5.5.5 |
| trueconf | trueconf_server | >= 5.5.0.13826 < 5.5.5.10010 | 5.5.5.10010 |
| trueconf | trueconf_server | >= 5.5.0.13828 < 5.5.5.10009 | 5.5.5.10009 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.09.3CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by ca
ghsa_unreviewed·2026-08-19
CVE-2026-72529 [CRITICAL] CWE-306 A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by ca
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
VulnCheck
TrueConf Server Missing Authentication for Critical Function Vulnerability
vulncheck·2026·CVSS 9.8
CVE-2026-72529 [CRITICAL] CWE-306 TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf Server Missing Authentication for Critical Function Vulnerability
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
Affected: TrueConf Server
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patchi
CISA
TrueConf Server Missing Authentication for Critical Function Vulnerability
cisa·2026-08-20·CVSS 9.8
CVE-2026-72529 [CRITICAL] CWE-306 TrueConf Server Missing Authentication for Critical Function Vulnerability
Vulnerability: TrueConf Server Missing Authentication for Critical Function Vulnerability
Affected: TrueConf Server
TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BO
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-19
Published
2026-08-20
Added to CISA KEV
Exploited in the wild