Fixing and finding

[Jump to remediation plan](#remediation)

CVE ID

# CVE-2026-72529

Published 2026-08-19

Updated 2 months ago

Vendor/s

TrueConf

Product/s

Server

Version/s

\* > 5.3.9.10013

KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.

CVSS Score (v3.1)

9.8

/ 10

Critical

Severity Details

Base score

9.8 Critical

Attack vector

Network

Attack complexity

Low

Privileges required

None

User interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Table of Contents

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

## Description

CVE-2026-72529 is a critical 9.8 CVSS vulnerability in TrueConf Server allowing remote script execution. Actively exploited; update to latest versions now.

## Why this matters

"CVE-2026-72529 is a critical vulnerability in TrueConf Server with a maximum CVSS score of 9.8, indicating extreme risk. It is currently listed on CISA’s Known Exploited Vulnerabilities (KEV) catalog, confirming that attackers are actively leveraging this flaw in the wild. The vulnerability allows a remote, unauthorized attacker to execute arbitrary scripts by accessing an undocumented function via port 4307/TCP. Because the attack requires no privileges or user interaction, any internet-exposed TrueConf instance is highly susceptible to full system compromise, data exfiltration, and lateral movement within the corporate network."

## CPE

TrueConf

| Product          | Version Start | Version End (excl.) | Status     |
| ---------------- | ------------- | ------------------- | ---------- |
| trueconf\_server | \*            | 5.3.9.10013         | vulnerable |
| trueconf\_server | \*            | 5.3.9.10015         | vulnerable |
| trueconf\_server | 5.4.0.12689   | 5.4.9.10072         | vulnerable |
| trueconf\_server | 5.4.0.12700   | 5.4.9.10019         | vulnerable |
| trueconf\_server | 5.5.0.13826   | 5.5.5.10010         | vulnerable |
| trueconf\_server | 5.5.0.13828   | 5.5.5.10009         | vulnerable |

## Related weakness (CWE)

CWE-306

## Remediation plan

1

### Apply official patches

Immediately download and install the security patches provided by TrueConf. The vendor has released updates that remove the undocumented function and enforce strict authentication requirements for all server operations.

2

### Update affected systems

Verify that TrueConf Server is running version 5.3.9.10015, 5.4.9.10072, 5.5.5.10010, or higher. Systems running versions 5.3.X, 5.4.X, or 5.5.X below these releases are confirmed vulnerable and must be updated.

3

### Restrict access

Use network firewalls or Access Control Lists (ACLs) to restrict access to port 4307/TCP. Ensure this port is not exposed to the public internet and is only accessible from trusted administrative segments of the internal network.

4

### Monitor for exploitation

Perform a forensic review of system logs for any unauthorized script execution or unusual API calls on port 4307. Check for the presence of web shells or new, unauthorized administrative accounts created during the window of vulnerability.

## Detection Guidance

"Detecting exploitation of CVE-2026-72529 involves monitoring network traffic for inbound connections to port 4307/TCP from external or untrusted sources. Security teams should analyze TrueConf Server logs for evidence of undocumented function calls or administrative commands executed without prior authentication. Look for indicators of compromise (IOCs) such as unexpected child processes spawned by the TrueConf service or the creation of suspicious scripts in temporary directories on the host system."

## References

[https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/ Third Party Advisory ](https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/)[https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/ Exploit Third Party Advisory ](https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/)[https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field\_cve=CVE-2026-72529 US Government Resource](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72529)

## Sources

NIST National Vulnerability Database (NVD)

CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](https://www.upguard.com/contact-sales)

[Free trial](https://www.upguard.com/demo)
