CISA added CVE-2026-72529, an unauthenticated arbitrary script execution flaw in TrueConf Server reachable over port 4307/TCP, to the Known Exploited Vulnerabilities catalog on 2026-08-20 with a three-day remediation deadline.
What Is It
CVE-2026-72529 is a missing authentication for critical function vulnerability (CWE-306) in TrueConf Server. A remote, unauthorized attacker with network access to port 4307/TCP can call an undocumented function and execute an arbitrary script. No credentials, no user interaction, and no special conditions are required.
The flaw carries a CVSS v3.1 base score of 9.8 (Critical, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and a CVSS v4.0 score of 9.3 (Critical), with high impact to confidentiality, integrity, and availability. The CVE was published 2026-08-19 and is sourced to Kaspersky's ICS-CERT.
Why It Matters
CISA's KEV listing confirms active exploitation. CISA's SSVC decision record for this CVE scores exploitation as active, automatable as yes, and technical impact as total. Ransomware campaign use is listed as Unknown.
NVD references a Securelist writeup tagged as an exploit resource: Head Mare targets TrueConf Server with PhantomCore. Combined with an unauthenticated network-facing entry point and low attack complexity, any internet-exposed TrueConf Server should be treated as a live target.
What's Vulnerable
TrueConf Server on both Windows and Linux, in these branches:
- All versions prior to 5.3
- 5.3.x before 5.3.9 (Windows: < 5.3.9.10013; Linux: < 5.3.9.10015)
- 5.4.x before 5.4.9 (Windows: < 5.4.9.10072; Linux: < 5.4.9.10019)
- 5.5.x before 5.5.5 (Windows: < 5.5.5.10010; Linux: < 5.5.5.10009)
Patch Status
CISA's required action: apply mitigations per vendor instructions in accordance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.
Due date: 2026-08-23: three days from KEV addition. Vendor fixes are tracked on TrueConf's security advisories page.
Sources
- CISA KEV Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72529
- NVD, CVE-2026-72529, https://nvd.nist.gov/vuln/detail/CVE-2026-72529
- Kaspersky ICS-CERT Advisory; https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/
- Securelist, Head Mare targets TrueConf Server with PhantomCore, https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/
- TrueConf Security Fixes, Updates and Advisories; https://trueconf.com/blog/news/security-fixes-updates-and-advisories
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk