Category: CISA Advisories
Let me ask you something: if someone could walk up to your office building, bypass the front desk, and take control of a critical room without a key, how quickly would you want that door locked?
That is the practical concern behind two TrueConf Server vulnerabilities added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog on August 20, 2026. Both vulnerabilities can be reached remotely through TCP port 4307, and neither requires the attacker to authenticate first.
If your business uses TrueConf Server, inventory and remediation should begin immediately.
The two TrueConf Server vulnerabilities
CISA added these vulnerabilities because they are known to be exploited in the wild. CISA currently lists ransomware use as unknown for both vulnerabilities, but that does not make them low risk.
The vulnerabilities affect TrueConf Server installations running:
- All versions before 5.3
- 5.3.x versions earlier than 5.3.9
- 5.4.x versions earlier than 5.4.9
- 5.5.x versions earlier than 5.5.5
TrueConf identifies versions 5.3.9, 5.4.9, and 5.5.5 as resolution versions for the affected release branches. Use the newest supported release available for your environment.
CVE-2026-72529: Missing authentication for a critical function
CVE-2026-72529 is a missing authentication vulnerability, classified as CWE-306.
In plain English, TrueConf Server exposes a critical function that does not properly check who is calling it. An unauthorized remote attacker with network access to TCP port 4307 could call that undocumented function and execute an arbitrary script on the server.
The vulnerability carries a CVSS score of 9.8, which is critical.
CISA lists the remediation due date as August 23, 2026.
That is only a short window from the August 20 catalog addition. If you operate an affected server, waiting for a normal monthly maintenance cycle is not a safe plan.
CVE-2026-72530: Code injection and escape from the isolated environment
CVE-2026-72530 is a code injection vulnerability, classified as CWE-94.
TrueConf Server is designed to run scripts inside an isolated environment. Think of that environment as a locked room where a process is supposed to stay contained.
The vulnerability may allow an unauthorized remote attacker with access to TCP port 4307 to use a specially crafted script to escape that isolated environment and execute arbitrary code on the host system. In other words, the attacker may move from controlling a restricted process to controlling the underlying server.
The vulnerability carries a CVSS score of 9.0.
CISA lists the remediation due date as September 3, 2026.
The deadlines are different, but both vulnerabilities should be handled together. An attacker who gains script execution may attempt to use the second flaw to reach the host operating system.

Why this matters to your business
You may be thinking, “Our TrueConf Server is not directly exposed to the internet, so are we really at risk?”
That is an important question. But “not internet-facing” does not automatically mean “safe.”
An attacker may still reach the server through:
- A compromised workstation on your internal network
- A breached VPN account
- A misconfigured firewall or port-forwarding rule
- A flat network with too little segmentation
- A cloud or hosted deployment with unexpected exposure
- A trusted partner connection
If an attacker can reach TCP port 4307, the vulnerabilities may provide a path to execute scripts or code without valid credentials.
And here's where it gets serious: a compromised TrueConf Server could affect more than video conferencing. The server may contain configuration data, credentials, communications, logs, and connections to other business systems.
Successful exploitation could lead to:
- Unauthorized access to the server
- Exposure or modification of sensitive information
- Disruption of meetings and communications
- Malware installation
- Credential theft
- Lateral movement into other systems
- Tampering with software or files distributed through the server
Kaspersky ICS CERT has also advised organizations to check for indicators of compromise associated with reported exploitation and the PhantomCore malware campaign. That means patching is essential, but patching alone may not be enough if the server was already accessed.
It makes sense to fix the door. You should also check whether someone already came through it.
What you should do now
Start with inventory. You cannot protect a server you do not know exists.
1. Identify every TrueConf Server installation
Check production, backup, disaster recovery, test, and lab environments.
Record:
- TrueConf Server version
- Windows or Linux operating system
- Server location
- Internet, VPN, or internal exposure
- Firewall rules involving TCP port 4307
- System owner and business purpose
- Whether the server is hosted by a provider or operated internally
Do not assume there is only one installation. Older systems are often left running after a replacement or migration.
2. Confirm whether TCP port 4307 is reachable
Review firewall, router, VPN, and cloud security-group rules.
The goal is to ensure TCP port 4307 is not exposed to the public internet or unnecessary network segments. Restrict access to trusted administrative or application networks wherever possible.
Network restrictions are a useful temporary safeguard, but they are not a substitute for upgrading. If an attacker is already inside your network, an internally reachable vulnerable service may still be exposed.
3. Upgrade to a fixed version
Follow TrueConf’s official security guidance and update procedures.
The affected branches are addressed by:
- TrueConf Server 5.3.9
- TrueConf Server 5.4.9
- TrueConf Server 5.5.5
A newer supported release may also be appropriate. Confirm the final version with TrueConf before making changes to a production system.
After the update, verify that the corrected version is actually running. Document the change and confirm that backup or standby systems were not overlooked.
4. Perform a compromise check
Because these vulnerabilities are listed in CISA’s KEV Catalog, treat the work as both remediation and security triage.
Review:
- TrueConf Server logs
- Connections to TCP port 4307
- Unexpected script activity
- New or modified executables
- Unusual administrator accounts
- New scheduled tasks or services
- Unexpected outbound network connections
- Changes to client installers or distributed files
- Antivirus and endpoint detection alerts
Run current antivirus and endpoint security scans on the server. If you find suspicious activity, isolate the system when practical and begin incident-response procedures before rebuilding or deleting evidence.
CISA also points organizations toward its Forensics Triage Requirements under BOD 26-04. Follow that guidance where it applies to your organization.

What CISA’s KEV listing means
CISA’s KEV Catalog is not simply another list of theoretical software bugs. It is CISA’s authoritative collection of vulnerabilities known to have been exploited in the wild.
CISA recommends using the catalog to prioritize vulnerability management. For federal civilian executive branch agencies, KEV remediation requirements apply through Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk.
For these TrueConf vulnerabilities, the catalog lists:
| Vulnerability | Issue | Date added | CISA due date | Ransomware use |
|---|---|---|---|---|
| CVE-2026-72529 | Missing authentication for a critical function; arbitrary script execution | August 20, 2026 | August 23, 2026 | Unknown |
| CVE-2026-72530 | Code injection; escape from isolated environment; host code execution | August 20, 2026 | September 3, 2026 | Unknown |
Even if your business is not a federal agency, the deadlines are a useful signal. Known exploitation, remote access, no required user interaction, and potential host takeover make these vulnerabilities urgent for any organization using the product.
Official sources and update guidance
For technical details and remediation information, review:
- TrueConf security fixes, updates, and advisories
- Kaspersky ICS CERT: TrueConf Server missing authentication for a critical function
- Kaspersky ICS CERT: TrueConf Server breakout from isolated environment
- CISA Known Exploited Vulnerabilities Catalog
- CISA BOD 26-04: Prioritizing Security Updates Based on Risk
You can also review our plain-English guide to CISA threat alerts for more context on how KEV advisories affect business decisions.

The bottom line
If your business uses TrueConf Server, find every installation, check the version, restrict TCP port 4307, upgrade to a fixed release, and investigate for signs of compromise.
CVE-2026-72529 has a CISA due date of August 23. CVE-2026-72530 is due September 3. The first deadline is close, and known exploitation means this should not wait for a convenient time.
It is not about blame. It is about knowing which doors are open and making sure your business controls who gets inside.
If you would like help with inventory, patching, firewall review, or incident triage, contact Platinum Web Services. We help small businesses manage urgent security issues and keep their technology protected with 24/7 support.


0 Comments