CVE-2026-72529 is a critical 9.8 CVSS vulnerability in TrueConf Server allowing remote script execution. Actively exploited; update to latest versions now.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| trueconf_server | * | 5.3.9.10013 | vulnerable |
| trueconf_server | * | 5.3.9.10015 | vulnerable |
| trueconf_server | 5.4.0.12689 | 5.4.9.10072 | vulnerable |
| trueconf_server | 5.4.0.12700 | 5.4.9.10019 | vulnerable |
| trueconf_server | 5.5.0.13826 | 5.5.5.10010 | vulnerable |
| trueconf_server | 5.5.0.13828 | 5.5.5.10009 | vulnerable |
Immediately download and install the security patches provided by TrueConf. The vendor has released updates that remove the undocumented function and enforce strict authentication requirements for all server operations.
Verify that TrueConf Server is running version 5.3.9.10015, 5.4.9.10072, 5.5.5.10010, or higher. Systems running versions 5.3.X, 5.4.X, or 5.5.X below these releases are confirmed vulnerable and must be updated.
Use network firewalls or Access Control Lists (ACLs) to restrict access to port 4307/TCP. Ensure this port is not exposed to the public internet and is only accessible from trusted administrative segments of the internal network.
Perform a forensic review of system logs for any unauthorized script execution or unusual API calls on port 4307. Check for the presence of web shells or new, unauthorized administrative accounts created during the window of vulnerability.
"Detecting exploitation of CVE-2026-72529 involves monitoring network traffic for inbound connections to port 4307/TCP from external or untrusted sources. Security teams should analyze TrueConf Server logs for evidence of undocumented function calls or administrative commands executed without prior authentication. Look for indicators of compromise (IOCs) such as unexpected child processes spawned by the TrueConf service or the creation of suspicious scripts in temporary directories on the host system."
Experience superior visibility and a simpler approach to cyber risk management