SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-72529

CRITICAL · CVSS 9.8 EPSS 1.55% CISA KEV · Actively Exploited

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, and 5.5.X to 5.5.5 are vulnerable to remote code execution due to an undocumented function accessible via port 4307/TCP. This critical vulnerability allows unauthorized attackers with network access to execute arbitrary scripts, potentially compromising the server's integrity and confidentiality. Organizations using affected TrueConf server versions should prioritize immediate remediation to mitigate the risk of exploitation.

CISA KEV Details

Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.

Ransomware use: Unknown

Added to KEV: 2026-08-20

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE
CVE-2026-72529
Severity
CRITICAL
CVSS
9.8
EPSS
1.55%

Original NVD Description

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Related CVEs

Other vulnerabilities affecting the same vendor(s)