• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-72530: pre-auth remote code execution in TrueConf Server

An unauthenticated remote attacker can execute arbitrary code on TrueConf Server by sending a specially crafted script to the product's network service on port 4307/TCP. CVE-2026-72530 is a code injection flaw (CWE-94) that affects multiple 5.x branches: versions before 5.3, 5.3 through before 5.3.9, 5.4 through before 5.4.9, and 5.5 through before 5.5.5. An attacker only needs network access to the service port; no user interaction or credentials are required.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9CRITICAL
EPSS
0.01686
CWE
CWE-94
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: CISA added this flaw to its Known Exploited Vulnerabilities catalog with a federal mitigation deadline, and public exploit code is available — prioritize patching or mitigations for any internet-facing TrueConf Server.

What is CVE-2026-72530?

An unauthenticated remote attacker can execute arbitrary code on TrueConf Server by sending a specially crafted script to the product's network service on port 4307/TCP. CVE-2026-72530 is a code injection flaw (CWE-94) that affects multiple 5.x branches: versions before 5.3, 5.3 through before 5.3.9, 5.4 through before 5.4.9, and 5.5 through before 5.5.5. An attacker only needs network access to the service port; no user interaction or credentials are required.

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Which versions of TrueConf Server are affected?

BRANCHAFFECTEDFIXED
5.xbefore 5.35.3
5.x5.3 – before 5.3.95.3.9
5.x5.4 – before 5.4.95.4.9
5.x5.5 – before 5.5.55.5.5

Is CVE-2026-72530 being exploited?

CISA added CVE-2026-72530 to the Known Exploited Vulnerabilities catalog on 2026-08-20, and U.S. federal agencies were required to apply mitigations or patches by 2026-09-03; public exploit code is available.

How to fix CVE-2026-72530

  1. Upgrade TrueConf Server to a fixed release: 5.3, 5.3.9, 5.4.9, or 5.5.5 as appropriate for your branch.
  2. If you cannot immediately upgrade, restrict network access to port 4307/TCP to trusted hosts only and block it at the edge for internet-facing systems.
  3. Follow vendor guidance and monitor TrueConf Server logs and host telemetry for signs of code execution or unexpected process activity.
  4. Apply CISA KEV mitigation guidance where applicable and document compliance with BOD 26-04 requirements.

Frequently asked questions

Is CVE-2026-72530 being actively exploited?

CISA added CVE-2026-72530 to its Known Exploited Vulnerabilities catalog on 2026-08-20 requiring federal action by 2026-09-03, and public exploit code is available.

Which TrueConf Server versions are affected by CVE-2026-72530?

TrueConf Server versions before 5.3, 5.3 up to before 5.3.9, 5.4 up to before 5.4.9, and 5.5 up to before 5.5.5 are affected.

Is there a patch for CVE-2026-72530?

Yes. Fixed releases are 5.3, 5.3.9, 5.4.9, and 5.5.5 for the respective affected branches.

Does CVE-2026-72530 require authentication?

No. The vulnerability can be exploited by an unauthenticated attacker with network access to TrueConf Server's port 4307/TCP.

References