CVE-2026-72529: A remote unauthorized attacker with network access via port
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
- CISA KEV-listed (remediation due 2026-08-23)
- EPSS 1.5% (72.9% percentile)
- CVSS 9.3 critical
Related briefings
- US warns two critical TrueConf server flaws are exploited 2026-08-20
- Hackers backdoor TrueConf servers to infect meeting guests 2026-08-11
Linked threat actors
- Head Mare machine-inferred link