CVE-2026-72530
published 2026-08-19CVE-2026-72530: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and…
PriorityP189critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-09-03
Exploited in the wild
EPSS
0.97%
58.9th percentile
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| trueconf | trueconf_server | < 5.3.9.10013 | 5.3.9.10013 |
| trueconf | trueconf_server | < 5.3.9.10015 | 5.3.9.10015 |
| trueconf | trueconf_server | >= * < 5.3 | 5.3 |
| trueconf | trueconf_server | >= 5.3 < 5.3.9 | 5.3.9 |
| trueconf | trueconf_server | >= 5.4 < 5.4.9 | 5.4.9 |
| trueconf | trueconf_server | >= 5.4.0.12689 < 5.4.9.10072 | 5.4.9.10072 |
| trueconf | trueconf_server | >= 5.4.0.12700 < 5.4.9.10019 | 5.4.9.10019 |
| trueconf | trueconf_server | >= 5.5 < 5.5.5 | 5.5.5 |
| trueconf | trueconf_server | >= 5.5.0.13826 < 5.5.5.10010 | 5.5.5.10010 |
| trueconf | trueconf_server | >= 5.5.0.13828 < 5.5.5.10009 | 5.5.5.10009 |
CVSS provenance
nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv4.09.5CRITICALCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck9.0CRITICAL
cisa9.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
TrueConf Server up to 5.2/5.3.8/5.4.8/5.5.4 improper authorization
vuldb·2026-08-20·CVSS 9.0
CVE-2026-72530 [CRITICAL] TrueConf Server up to 5.2/5.3.8/5.4.8/5.5.4 improper authorization
A vulnerability categorized as critical has been discovered in TrueConf Server up to 5.2/5.3.8/5.4.8/5.5.4. Affected by this issue is some unknown functionality. The manipulation results in improper authorization.
This vulnerability is known as CVE-2026-72530. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is advisable to upgrade the affected component.
GHSA
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to
ghsa_unreviewed·2026-08-19
CVE-2026-72530 [CRITICAL] CWE-94 A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
VulnCheck
TrueConf Server Code Injection Vulnerability
vulncheck·2026·CVSS 9.0
CVE-2026-72530 [CRITICAL] CWE-94 TrueConf Server Code Injection Vulnerability
TrueConf Server Code Injection Vulnerability
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Affected: TrueConf Server
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring
CISA
TrueConf Server Code Injection Vulnerability
cisa·2026-08-20·CVSS 9.0
CVE-2026-72530 [CRITICAL] CWE-94 TrueConf Server Code Injection Vulnerability
Vulnerability: TrueConf Server Code Injection Vulnerability
Affected: TrueConf Server
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposur
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-19
Published
2026-08-20
Added to CISA KEV
Exploited in the wild