• News/
  • bleepingcomputer-20260821122533

CISA orders feds to patch actively exploited TrueConf Server flaws

BleepingComputer
·
Sergiu Gatlan
·
Published Aug 21, 2026
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. TrueConf Server is designed for secure corporate messaging and video conferencing and, unlike cloud-based software like Zoom or Microsoft Teams, it operates inside an organization's local network (LAN). The most severe is a critical missing authentication security flaw (tracked as CVE-2026-72529) that allows attackers without privileges to remotely execute arbitrary scripts on unpatched servers. "A remote unauthenticated attacker connecting to TrueConf Server over 4307/TCP can invoke an undocumented critical function and execute an arbitrary script on the server," the TrueConf security team explains. The second is another critical severity vulnerability (CVE-2026-72530) that unauthenticated threat actors can exploit through high-complexity code injection attacks to gain remote code execution. "Improper management of code generation can allow an attacker who has achieved code execution in the TrueConf Server isolated environment to escape the sandbox and execute arbitrary commands on the underlying operating system," TrueConf adds. On Thursday, CISA added the two flaws to its KEV catalog and ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their servers within two weeks, by September 3. "This type of vulnerability is a frequent attack vect...

Read full article

Affected Software

3 affected components
TrueConf TrueConf Server self-hosted communications platform
TrueConf TrueConf Server isolated environment
TrueConf TrueConf Server

Frequently Asked Questions

1

Which TrueConf Server vulnerabilities are being actively exploited?

CISA added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities catalog. Both are rated critical and affect the TrueConf Server self-hosted communications platform.

2

What can an attacker do with CVE-2026-72529?

An unauthenticated remote attacker connecting to TrueConf Server over 4307/TCP can invoke an undocumented critical function and execute an arbitrary script on an unpatched server. No privileges are required.

3

How does CVE-2026-72530 differ from the other flaw?

CVE-2026-72530 involves high-complexity code injection and can lead to remote code execution. It may allow an attacker that has achieved code execution in the isolated TrueConf Server environment to escape the sandbox and execute arbitrary code.

4

What action does CISA require from federal agencies?

CISA ordered U.S. federal agencies to prioritize patching the two actively exploited TrueConf Server vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203