TrueConf Server Vulnerabilities Added to CISA’s KEV Catalog

Category: CISA Advisories

Let me ask you something: if someone could walk up to your office building, bypass the front desk, and take control of a critical room without a key, how quickly would you want that door locked?

That is the practical concern behind two TrueConf Server vulnerabilities added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog on August 20, 2026. Both vulnerabilities can be reached remotely through TCP port 4307, and neither requires the attacker to authenticate first.

If your business uses TrueConf Server, inventory and remediation should begin immediately.

The two TrueConf Server vulnerabilities

CISA added these vulnerabilities because they are known to be exploited in the wild. CISA currently lists ransomware use as unknown for both vulnerabilities, but that does not make them low risk.

The vulnerabilities affect TrueConf Server installations running:

  • All versions before 5.3
  • 5.3.x versions earlier than 5.3.9
  • 5.4.x versions earlier than 5.4.9
  • 5.5.x versions earlier than 5.5.5

TrueConf identifies versions 5.3.9, 5.4.9, and 5.5.5 as resolution versions for the affected release branches. Use the newest supported release available for your environment.

CVE-2026-72529: Missing authentication for a critical function

CVE-2026-72529 is a missing authentication vulnerability, classified as CWE-306.

In plain English, TrueConf Server exposes a critical function that does not properly check who is calling it. An unauthorized remote attacker with network access to TCP port 4307 could call that undocumented function and execute an arbitrary script on the server.

The vulnerability carries a CVSS score of 9.8, which is critical.

CISA lists the remediation due date as August 23, 2026.

That is only a short window from the August 20 catalog addition. If you operate an affected server, waiting for a normal monthly maintenance cycle is not a safe plan.

CVE-2026-72530: Code injection and escape from the isolated environment

CVE-2026-72530 is a code injection vulnerability, classified as CWE-94.

TrueConf Server is designed to run scripts inside an isolated environment. Think of that environment as a locked room where a process is supposed to stay contained.

The vulnerability may allow an unauthorized remote attacker with access to TCP port 4307 to use a specially crafted script to escape that isolated environment and execute arbitrary code on the host system. In other words, the attacker may move from controlling a restricted process to controlling the underlying server.

The vulnerability carries a CVSS score of 9.0.

CISA lists the remediation due date as September 3, 2026.

The deadlines are different, but both vulnerabilities should be handled together. An attacker who gains script execution may attempt to use the second flaw to reach the host operating system.

IT consultant inspecting a business network cabinet and firewall equipment

Why this matters to your business

You may be thinking, “Our TrueConf Server is not directly exposed to the internet, so are we really at risk?”

That is an important question. But “not internet-facing” does not automatically mean “safe.”

An attacker may still reach the server through:

  • A compromised workstation on your internal network
  • A breached VPN account
  • A misconfigured firewall or port-forwarding rule
  • A flat network with too little segmentation
  • A cloud or hosted deployment with unexpected exposure
  • A trusted partner connection

If an attacker can reach TCP port 4307, the vulnerabilities may provide a path to execute scripts or code without valid credentials.

And here's where it gets serious: a compromised TrueConf Server could affect more than video conferencing. The server may contain configuration data, credentials, communications, logs, and connections to other business systems.

Successful exploitation could lead to:

  • Unauthorized access to the server
  • Exposure or modification of sensitive information
  • Disruption of meetings and communications
  • Malware installation
  • Credential theft
  • Lateral movement into other systems
  • Tampering with software or files distributed through the server

Kaspersky ICS CERT has also advised organizations to check for indicators of compromise associated with reported exploitation and the PhantomCore malware campaign. That means patching is essential, but patching alone may not be enough if the server was already accessed.

It makes sense to fix the door. You should also check whether someone already came through it.

What you should do now

Start with inventory. You cannot protect a server you do not know exists.

1. Identify every TrueConf Server installation

Check production, backup, disaster recovery, test, and lab environments.

Record:

  • TrueConf Server version
  • Windows or Linux operating system
  • Server location
  • Internet, VPN, or internal exposure
  • Firewall rules involving TCP port 4307
  • System owner and business purpose
  • Whether the server is hosted by a provider or operated internally

Do not assume there is only one installation. Older systems are often left running after a replacement or migration.

2. Confirm whether TCP port 4307 is reachable

Review firewall, router, VPN, and cloud security-group rules.

The goal is to ensure TCP port 4307 is not exposed to the public internet or unnecessary network segments. Restrict access to trusted administrative or application networks wherever possible.

Network restrictions are a useful temporary safeguard, but they are not a substitute for upgrading. If an attacker is already inside your network, an internally reachable vulnerable service may still be exposed.

3. Upgrade to a fixed version

Follow TrueConf’s official security guidance and update procedures.

The affected branches are addressed by:

  • TrueConf Server 5.3.9
  • TrueConf Server 5.4.9
  • TrueConf Server 5.5.5

A newer supported release may also be appropriate. Confirm the final version with TrueConf before making changes to a production system.

After the update, verify that the corrected version is actually running. Document the change and confirm that backup or standby systems were not overlooked.

4. Perform a compromise check

Because these vulnerabilities are listed in CISA’s KEV Catalog, treat the work as both remediation and security triage.

Review:

  • TrueConf Server logs
  • Connections to TCP port 4307
  • Unexpected script activity
  • New or modified executables
  • Unusual administrator accounts
  • New scheduled tasks or services
  • Unexpected outbound network connections
  • Changes to client installers or distributed files
  • Antivirus and endpoint detection alerts

Run current antivirus and endpoint security scans on the server. If you find suspicious activity, isolate the system when practical and begin incident-response procedures before rebuilding or deleting evidence.

CISA also points organizations toward its Forensics Triage Requirements under BOD 26-04. Follow that guidance where it applies to your organization.

Business owner and IT consultant reviewing an asset checklist during a security response meeting

What CISA’s KEV listing means

CISA’s KEV Catalog is not simply another list of theoretical software bugs. It is CISA’s authoritative collection of vulnerabilities known to have been exploited in the wild.

CISA recommends using the catalog to prioritize vulnerability management. For federal civilian executive branch agencies, KEV remediation requirements apply through Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk.

For these TrueConf vulnerabilities, the catalog lists:

Vulnerability Issue Date added CISA due date Ransomware use
CVE-2026-72529 Missing authentication for a critical function; arbitrary script execution August 20, 2026 August 23, 2026 Unknown
CVE-2026-72530 Code injection; escape from isolated environment; host code execution August 20, 2026 September 3, 2026 Unknown

Even if your business is not a federal agency, the deadlines are a useful signal. Known exploitation, remote access, no required user interaction, and potential host takeover make these vulnerabilities urgent for any organization using the product.

Official sources and update guidance

For technical details and remediation information, review:

You can also review our plain-English guide to CISA threat alerts for more context on how KEV advisories affect business decisions.

IT specialist applying a secure software update at a modern workstation

The bottom line

If your business uses TrueConf Server, find every installation, check the version, restrict TCP port 4307, upgrade to a fixed release, and investigate for signs of compromise.

CVE-2026-72529 has a CISA due date of August 23. CVE-2026-72530 is due September 3. The first deadline is close, and known exploitation means this should not wait for a convenient time.

It is not about blame. It is about knowing which doors are open and making sure your business controls who gets inside.

If you would like help with inventory, patching, firewall review, or incident triage, contact Platinum Web Services. We help small businesses manage urgent security issues and keep their technology protected with 24/7 support.

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *