๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-72530: TrueConf Server Code Injection Vulnerability
Summary
TrueConf Server has a code injection vulnerability (a flaw where attackers can insert malicious code) that allows an unauthorized attacker with network access to port 4307/TCP to escape the isolated environment and run arbitrary code (commands of their choice) on the host system. This vulnerability is actively being exploited in the wild. The deadline to apply fixes is September 3, 2026.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 (a directive on prioritizing security updates based on risk). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. See the vendor's security advisories page at https://trueconf.com/blog/news/security-fixes-updates-and-advisories for specific patch or update instructions.
Vulnerability Details
EPSS: 0.3%
Yes
๐ฅ Actively Exploited
August 19, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-72530
First tracked: August 20, 2026 at 02:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%