## Overview
CISA added CVE-2026-72529 to its Known Exploited Vulnerabilities (KEV) list on August 20, 2026. This vulnerability affects TrueConf Server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, and 5.5.X to 5.5.5. The inclusion in the KEV list signals a federal deadline for remediation due to active exploitation evidence.
## Technical Details
The vulnerability arises from missing authentication for critical functions. Attackers can exploit this flaw by accessing the TrueConf server via port 4307/TCP. Once inside, they can execute arbitrary scripts by calling undocumented functions. The lack of proper authentication mechanisms makes this exploitation straightforward for unauthorized users with network access.
## Impact
Successful exploitation of CVE-2026-72529 allows remote attackers to run arbitrary scripts on affected TrueConf servers. This could lead to unauthorized access, data manipulation, or further compromise of the server environment. Given the CVSS score of 9.3, the risk level is critical, necessitating immediate action from organizations using the affected versions.
## Mitigation
Organizations running TrueConf Server should upgrade to the latest patched versions immediately. Ensure that all instances are updated beyond version 5.5.5 to mitigate the risk. Additionally, restrict access to port 4307/TCP from untrusted networks. Implementing network segmentation and access controls can further reduce exposure to this vulnerability.
CSURFACE Threat Sensor