Fixing and finding

[Jump to remediation plan](#remediation)

CVE ID

# CVE-2026-72530

Published 2026-08-19

Updated 2 months ago

Vendor/s

TrueConf

Product/s

Server

Version/s

\* > 5.3.9.10013

KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.

CVSS Score (v3.1)

9

/ 10

Critical

Severity Details

Base score

9 Critical

Attack vector

Network

Attack complexity

High

Privileges required

None

User interaction

None

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Table of Contents

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

## Description

Critical RCE in TrueConf Server (CVE-2026-72530) allows remote attackers to escape isolation via port 4307. Active exploitation reported; patch now.

## Why this matters

"CVE-2026-72530 is a critical vulnerability with a CVSS score of 9.0, affecting TrueConf Server. It allows unauthorized remote attackers to execute arbitrary code on the host system by breaking out of the isolated environment via port 4307/TCP. This vulnerability is of significant concern to security teams because it is actively exploited (KEV-listed), meaning threat actors are currently leveraging this flaw in the wild. Organizations using TrueConf Server versions 5.3.x through 5.5.x are at immediate risk of full system compromise, data theft, and persistent network access if this vulnerability is left unaddressed."

## CPE

TrueConf

| Product          | Version Start | Version End (excl.) | Status     |
| ---------------- | ------------- | ------------------- | ---------- |
| trueconf\_server | \*            | 5.3.9.10013         | vulnerable |
| trueconf\_server | \*            | 5.3.9.10015         | vulnerable |
| trueconf\_server | 5.4.0.12689   | 5.4.9.10072         | vulnerable |
| trueconf\_server | 5.4.0.12700   | 5.4.9.10019         | vulnerable |
| trueconf\_server | 5.5.0.13826   | 5.5.5.10010         | vulnerable |
| trueconf\_server | 5.5.0.13828   | 5.5.5.10009         | vulnerable |

## Related weakness (CWE)

CWE-94

## Remediation plan

1

### Apply official patches

Immediately download and install the security patches provided by TrueConf. The vendor has released specific updates to address the sandbox escape mechanism and prevent unauthorized remote code execution.

2

### Update affected systems

Ensure all TrueConf Server instances are updated to versions 5.3.9.10015, 5.4.9.10072, 5.5.5.10010, or later. Verify that your current installation version is no longer within the vulnerable ranges identified in the CPE data.

3

### Restrict access

Implement strict firewall rules to control access to port 4307/TCP. Use a 'deny-all' strategy by default and only permit connections from known, trusted IP addresses or internal management segments to minimize exposure to remote attackers.

4

### Monitor for exploitation

Perform a forensic audit of TrueConf Server logs and host system activity. Look for evidence of unauthorized script execution, unexpected child processes originating from the TrueConf service, or suspicious network beacons following port 4307 activity.

## Detection Guidance

"Detecting exploitation of CVE-2026-72530 requires monitoring for unusual traffic patterns on port 4307/TCP. Security teams should look for inbound connections containing malformed scripts or payloads indicative of a sandbox escape. Additionally, monitor host-level logs for the creation of unauthorized shells or system-level processes by the TrueConf service account. Implementing EDR signatures to flag 'isolated environment' breakout attempts and reviewing CISA's forensics triage requirements will help identify active compromises."

## References

[https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-breakout-from-isolated-environment/ Third Party Advisory ](https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-breakout-from-isolated-environment/)[https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/ Exploit Third Party Advisory ](https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/)[https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field\_cve=CVE-2026-72530 US Government Resource](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72530)

## Sources

NIST National Vulnerability Database (NVD)

CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](https://www.upguard.com/contact-sales)

[Free trial](https://www.upguard.com/demo)
