SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-72529 2026-08-20

TrueConf Server Missing Authentication Flaw (CVE-2026-72529) Lands in CISA KEV

"CISA added CVE-2026-72529, an unauthenticated arbitrary script execution flaw in TrueConf Server reachable over port 4307/TCP, to the Known Exploited Vulnerabilities catalog on 2026-08-20 with a three-day remediation…"

CISA added CVE-2026-72529, an unauthenticated arbitrary script execution flaw in TrueConf Server reachable over port 4307/TCP, to the Known Exploited Vulnerabilities catalog on 2026-08-20 with a three-day remediation deadline.

What Is It

CVE-2026-72529 is a missing authentication for critical function vulnerability (CWE-306) in TrueConf Server. A remote, unauthorized attacker with network access to port 4307/TCP can call an undocumented function and execute an arbitrary script. No credentials, no user interaction, and no special conditions are required.

The flaw carries a CVSS v3.1 base score of 9.8 (Critical, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) and a CVSS v4.0 score of 9.3 (Critical), with high impact to confidentiality, integrity, and availability. The CVE was published 2026-08-19 and is sourced to Kaspersky's ICS-CERT.

Why It Matters

CISA's KEV listing confirms active exploitation. CISA's SSVC decision record for this CVE scores exploitation as active, automatable as yes, and technical impact as total. Ransomware campaign use is listed as Unknown.

NVD references a Securelist writeup tagged as an exploit resource: Head Mare targets TrueConf Server with PhantomCore. Combined with an unauthenticated network-facing entry point and low attack complexity, any internet-exposed TrueConf Server should be treated as a live target.

What's Vulnerable

TrueConf Server on both Windows and Linux, in these branches:

Patch Status

CISA's required action: apply mitigations per vendor instructions in accordance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.

Due date: 2026-08-23: three days from KEV addition. Vendor fixes are tracked on TrueConf's security advisories page.

Sources