[KEV] CVE-2026-72529 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-72529 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-72529 is a missing authentication vulnerability in TrueConf Server that exposes a critical function over TCP port 4307 and can allow an unauthenticated remote attacker to execute arbitrary scripts.
Technical Detail
The flaw is an authentication bypass affecting a critical TrueConf Server function accessible through the network service on port 4307/TCP. An attacker with network access to that port may be able to invoke the affected function without valid credentials and execute an arbitrary script. Successful exploitation can result in remote code execution on the TrueConf Server host, subject to the privileges of the vulnerable service.
Exploitation Status
Exploit maturity is assessed as Operational, meaning exploitation methods are sufficiently developed for practical use by attackers. CISA has confirmed active exploitation in the wild. The vulnerability was added to CISA's Known Exploited Vulnerabilities Catalog on August 20, 2026.
Who Is Targeting This
No confirmed threat actor attribution is available. Reported (research-inferred): no public attribution has been identified; reporting discusses CVE-2026-72529 alongside CVE-2026-72530 as a potential TrueConf Server takeover vector, but does not name specific threat groups or ransomware operators.
What To Do
Treat this as an urgent patching priority and apply the vendor-provided TrueConf Server security update as soon as it is available. CISA Known Exploited Vulnerabilities requirements direct federal civilian executive branch agencies to patch by September 10, 2026, or apply mitigations. Until remediation is complete, restrict TCP port 4307 access to only trusted administrative networks and block Internet exposure. Review TrueConf Server and host logs for unexpected connections to port 4307, unauthorized script execution, unusual child processes spawned by the TrueConf Server service, and unexplained configuration changes. No specific detection signatures or threat actor indicators are publicly confirmed.