DIRAS TAKE
Urgent: CISA added this flaw to its Known Exploited Vulnerabilities catalog with a federal mitigation deadline, and public exploit code is available — prioritize patching or mitigations for any internet-facing TrueConf Server.
What is CVE-2026-72530?
An unauthenticated remote attacker can execute arbitrary code on TrueConf Server by sending a specially crafted script to the product's network service on port 4307/TCP. CVE-2026-72530 is a code injection flaw (CWE-94) that affects multiple 5.x branches: versions before 5.3, 5.3 through before 5.3.9, 5.4 through before 5.4.9, and 5.5 through before 5.5.5. An attacker only needs network access to the service port; no user interaction or credentials are required.
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of TrueConf Server are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 5.x | before 5.3 | 5.3 |
| 5.x | 5.3 – before 5.3.9 | 5.3.9 |
| 5.x | 5.4 – before 5.4.9 | 5.4.9 |
| 5.x | 5.5 – before 5.5.5 | 5.5.5 |
Is CVE-2026-72530 being exploited?
CISA added CVE-2026-72530 to the Known Exploited Vulnerabilities catalog on 2026-08-20, and U.S. federal agencies were required to apply mitigations or patches by 2026-09-03; public exploit code is available.
How to fix CVE-2026-72530
- Upgrade TrueConf Server to a fixed release: 5.3, 5.3.9, 5.4.9, or 5.5.5 as appropriate for your branch.
- If you cannot immediately upgrade, restrict network access to port 4307/TCP to trusted hosts only and block it at the edge for internet-facing systems.
- Follow vendor guidance and monitor TrueConf Server logs and host telemetry for signs of code execution or unexpected process activity.
- Apply CISA KEV mitigation guidance where applicable and document compliance with BOD 26-04 requirements.
Frequently asked questions
Is CVE-2026-72530 being actively exploited?
CISA added CVE-2026-72530 to its Known Exploited Vulnerabilities catalog on 2026-08-20 requiring federal action by 2026-09-03, and public exploit code is available.
Which TrueConf Server versions are affected by CVE-2026-72530?
TrueConf Server versions before 5.3, 5.3 up to before 5.3.9, 5.4 up to before 5.4.9, and 5.5 up to before 5.5.5 are affected.
Is there a patch for CVE-2026-72530?
Yes. Fixed releases are 5.3, 5.3.9, 5.4.9, and 5.5.5 for the respective affected branches.
Does CVE-2026-72530 require authentication?
No. The vulnerability can be exploited by an unauthenticated attacker with network access to TrueConf Server's port 4307/TCP.
References
- nvd.nist.gov/vuln/detail/CVE-2026-72530
- cve.org/CVERecord?id=CVE-2026-72530
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72530
- ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-breakout-from-isolated-environment
- All TrueConf CVEs on CVE Radar
- CVEs published in September 2026