Remote Code Execution Vulnerability in TrueConf Server by TrueConf
CVE-2026-72529
Key Information:
- Vendor
Trueconf
- Status
- Vendor
- CVE Published:
- 19 August 2026
Badges
What is CVE-2026-72529?
CVE-2026-72529 is a remote code execution vulnerability identified in the TrueConf Server, a communication platform that facilitates video conferencing and collaboration for organizations. This flaw affects specific versions of the server—5.3.X to 5.3.9, 5.4.X to 5.4.9, and 5.5.X to 5.5.5—allowing unauthorized remote attackers with access to the network via TCP port 4307 to execute arbitrary scripts. The vulnerability arises from a lack of proper authentication for a critical undocumented function, making it easier for malicious actors to gain control over the server. If successfully exploited, this vulnerability could severely disrupt organizational operations, compromise sensitive information, and facilitate further attacks within the network.
Potential impact of CVE-2026-72529
-
Unauthorized Access and Control: The ability to execute arbitrary scripts gives attackers complete control over the affected TrueConf Server instance. This could lead to unauthorized data access, manipulation of system settings, or deployment of malicious payloads.
-
Service Disruption: Successful exploitation may result in significant service interruptions, affecting video conferencing and collaboration tools that organizations rely on. This can hamper communications, disrupt business operations, and lead to financial losses.
-
Data Breaches: With access to sensitive data through the compromised server, attackers can leak confidential organizational information or use it for further attacks. This can result in reputational damage and potential legal ramifications for organizations, particularly those handling sensitive or regulated data.
CISA has reported CVE-2026-72529
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-72529 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
TrueConf Server Windows * < 5.3
TrueConf Server Windows 5.3 < 5.3.9
TrueConf Server Windows 5.4 < 5.4.9
News Articles
CISA Orders Agencies to Patch Exploited TrueConf Flaws
CISA ordered civilian agencies to patch two exploited TrueConf Server flaws used to compromise systems and distribute trojanized client installers.
2 weeks ago
TrueConf flaws enabling attacks on meeting participants added to KEV catalog
The flaws have been used by the Head Mare APT hacktivist group to spread PhantomCore malware.
3 weeks ago
CISA orders feds to patch actively exploited TrueConf Server flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform.
3 weeks ago
References
CVSS V4
Timeline
- 💰
Used in Ransomware
- 📰
First article discovered by BleepingComputer
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published
Vulnerability Reserved
