DIRAS TAKE
Urgent: CISA added this flaw to the Known Exploited Vulnerabilities catalog with a rapid remediation deadline, so prioritize patching to the fixed releases or apply vendor mitigations immediately for internet-facing instances.
What is CVE-2026-72529?
An unauthenticated remote attacker can execute arbitrary scripts on TrueConf Server, allowing full compromise of the appliance. CVE-2026-72529 affects TrueConf Server versions before 5.3, 5.3 up to before 5.3.9, 5.4 up to before 5.4.9, and 5.5 up to before 5.5.5. Exploitation requires network access to the server's management port (port 4307/TCP) and involves calling an undocumented function that lacks authentication checks. The weakness is classified as CWE-306 (Missing Authentication for Critical Function).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of TrueConf Server are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 5.x | before 5.3 | 5.3 |
| 5.x | 5.3 – before 5.3.9 | 5.3.9 |
| 5.x | 5.4 – before 5.4.9 | 5.4.9 |
| 5.x | 5.5 – before 5.5.5 | 5.5.5 |
Is CVE-2026-72529 being exploited?
CISA added CVE-2026-72529 to the Known Exploited Vulnerabilities catalog on 2026-08-20, and US federal agencies were required to remediate by 2026-08-23.
How to fix CVE-2026-72529
- Upgrade TrueConf Server to one of the fixed releases: 5.3, 5.3.9, 5.4.9, or 5.5.5 as applicable for your branch.
- If you cannot upgrade immediately, block access to port 4307/TCP at network edge and firewall to prevent external access.
- Apply any vendor-recommended mitigations and configuration changes from TrueConf guidance.
- Monitor server logs and network traffic for suspicious calls to undocumented functions and signs of script execution.
Frequently asked questions
Is CVE-2026-72529 being actively exploited?
CISA added CVE-2026-72529 to its Known Exploited Vulnerabilities catalog on 2026-08-20, and US federal agencies were required to remediate by 2026-08-23.
Which TrueConf Server versions are affected by CVE-2026-72529?
TrueConf Server versions before 5.3, 5.3 up to before 5.3.9, 5.4 up to before 5.4.9, and 5.5 up to before 5.5.5 are affected.
Is there a patch for CVE-2026-72529?
Yes. TrueConf published fixes in versions 5.3, 5.3.9, 5.4.9, and 5.5.5; upgrade to the appropriate fixed release.
Does CVE-2026-72529 require authentication?
No. The vulnerability is a missing-authentication issue that allows unauthenticated callers with network access to port 4307/TCP to execute arbitrary scripts.
References
- nvd.nist.gov/vuln/detail/CVE-2026-72529
- cve.org/CVERecord?id=CVE-2026-72529
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72529
- ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function
- All TrueConf CVEs on CVE Radar
- CVEs published in September 2026