peter bassill · operator
$ cve CVE-2026-72529 JSON

CVE-2026-72529 KEV

9.8
CRITICAL · CVSS 3.1 · EPSS 1.5% (pctl 73)

Patch first

On CISA KEV — known exploited in the wild, due 2026-08-23.

Description

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.46% — more likely to be exploited than 73% of all CVEs
WeaknessCWE-306
On CISA KEVyes — remediate by 2026-08-23
Public exploitnone known
Published2026-08-19
Last modified2026-08-21

CISA KEV

NameTrueConf Server Missing Authentication for Critical Function Vulnerability
Added2026-08-20
Due2026-08-23
Vendor / productTrueConf / Server
Ransomware usenone reported

Affected (1)

VendorProduct
trueconftrueconf server

References

→ the Explorer  ·  watch your stack  ·  NVD