SYS::ONLINE
Wasteland.
Briefs2197
Issues24
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-72530 2026-08-20

CVE-2026-72530: Critical Code Injection in TrueConf Server Under Active Exploitation

"CISA added CVE-2026-72530 to the Known Exploited Vulnerabilities catalog on August 20, 2026, confirming active exploitation of a critical (CVSS 9.0) code injection flaw that lets unauthenticated attackers escape…"

CISA added CVE-2026-72530 to the Known Exploited Vulnerabilities catalog on August 20, 2026, confirming active exploitation of a critical (CVSS 9.0) code injection flaw that lets unauthenticated attackers escape TrueConf Server's isolated environment and run arbitrary code on the host.

What Is It

CVE-2026-72530 is a code injection vulnerability (CWE-94) in TrueConf Server. A remote, unauthorized attacker with network access to port 4307/TCP can submit a specially crafted script to break out of the server's isolated environment and execute arbitrary code on the underlying host system.

The flaw was reported by Kaspersky and carries a CVSS 3.1 base score of 9.0 (CRITICAL) with vector AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H. A CVSS 4.0 score of 9.5 (CRITICAL) is also assigned. The changed scope reflects the sandbox escape; impact extends past the vulnerable component to the host itself.

Why It Matters

No authentication and no user interaction are required. CISA's SSVC assessment marks exploitation as active with total technical impact, though it is not automatable and attack complexity is rated HIGH. NVD references a Securelist advisory tagged as an exploit resource describing the Head Mare threat actor targeting TrueConf Server with PhantomCore. Known ransomware campaign use is listed as Unknown.

Successful exploitation yields arbitrary code execution on the host. The CVSS metrics rate confidentiality, integrity, and availability impact as High with a changed scope, meaning the consequences reach past TrueConf Server itself to the underlying operating system. Whether an intrusion extends further, to adjacent or downstream systems, is not determined by the flaw alone; that depends on the host's privilege level, network position, and what credentials or trust relationships it holds.

What's Vulnerable

TrueConf Server on Windows and Linux, in these version ranges:

Patch Status

TrueConf has published security fixes and advisories. CISA's required action: apply mitigations per vendor instructions in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines.

Federal remediation due date: September 3, 2026.

Sources