Search
Find merged stories by title or summary.
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-72529 (CVSS score of 9.3) TrueConf Server Missing Authentication for Critical Function Vulnerability • CVE-2026-72530 (CVSS score of 9.5) TrueConf Server Code Injection Vulnerability TrueConf Server is an on-premises video conferencing and unified communications platform developed by TrueConf. Organizations can deploy it on their own infrastructure to provide secure video meetings, voice calls, messaging and collaboration without relying entirely on a cloud service.
TrueConf security advisory (AV26-835)
Serial Number: AV26-835 Date: August 20, 2026 As of August 19, 2026, TrueConf is affected by a vulnerability in the following product: • TrueConf Server • 5.3.x versions prior to 5.3.9 • 5.4.x versions prior to 5.4.9 • 5.5.x versions prior to 5.5.5 On August 20, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-72529 and CVE-2026-72530 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • TrueConf Security Vulnerabilities, Fixes and Advisories • CISA KEV: CVE-2026-72529 • CISA KEV: CVE-2026-72530 TrueConf security advisory (AV26-835) - Canadian Centre for Cyber Security
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability • CVE-2026-72530 TrueConf Server Code Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
CVE-2026-72530 - TrueConf Server Code Injection Vulnerability
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
You've reached the end of current stories for this search.
