US warns two critical TrueConf server flaws are exploited

CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog on August 20, saying it has evidence that attackers are using them in the wild. The National Vulnerability Database rates both critical, at 9.3 and 9.5 out of 10, and both can be reached by an attacker who has network access to the server and no account on it.

TrueConf Server is on-premises video conferencing software, the kind of system an organization runs itself so that meetings never leave its own network. Both flaws sit behind a single service port, 4307/TCP.

From an undocumented call to the host itself

NVD describes CVE-2026-72529 as an undocumented function that a remote unauthorized attacker can call over port 4307/TCP to execute an arbitrary script. CVE-2026-72530 goes a step further: a specially crafted script can break out of the isolated environment it runs in and execute code on the host system underneath. NVD lists versions 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5 and earlier as affected.

CISA's alert does not name the attackers, describe the intrusions or say how many organizations have been hit. That is normal for a catalog addition, and the agency has published nothing further.

Somebody was already inside TrueConf servers this month

Earlier in August, IntelFusions reported on an espionage campaign that chained two TrueConf Server flaws and then swapped out the client software the server hands to staff, so that anyone who downloaded the client got a backdoor with it. Kaspersky documented that activity, including the awkward detail that organizations which do not run TrueConf themselves could still be caught, because their people download the client from a partner's compromised server. CISA does not say whether that campaign is the exploitation behind this listing, and the two should not be treated as the same case until somebody establishes it.

Get past 5.5.5, and keep port 4307 off the internet

NVD lists everything up to and including 5.5.5 as vulnerable, which puts the fix in a later build. TrueConf's own advisory carries the exact version to move to, and administrators should work from that rather than from the version ranges in a CVE record. In the meantime, 4307/TCP has no business being reachable from the open internet; restrict it to the networks that actually need to reach the conferencing service, and review logs on any server that has been exposed rather than assuming it is clean, since exploitation is already happening somewhere.

Federal civilian agencies are bound by Binding Operational Directive 26-04, which tells them to prioritize rapid remediation of KEV listed flaws on publicly exposed assets that give an attacker total control of the asset after exploitation, and to check whether they were already compromised before the patch went on. CISA encourages every other organization to manage vulnerabilities the same way. The listing itself is in CISA's alert.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions