Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

[KEV] CVE-2026-72529 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2026-72529 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2026-72529 is a missing authentication vulnerability in TrueConf Server that exposes a critical function over TCP port 4307 and can allow an unauthenticated remote attacker to execute arbitrary scripts.

Technical Detail

The flaw is an authentication bypass affecting a critical TrueConf Server function accessible through the network service on port 4307/TCP. An attacker with network access to that port may be able to invoke the affected function without valid credentials and execute an arbitrary script. Successful exploitation can result in remote code execution on the TrueConf Server host, subject to the privileges of the vulnerable service.

Exploitation Status

Exploit maturity is assessed as Operational, meaning exploitation methods are sufficiently developed for practical use by attackers. CISA has confirmed active exploitation in the wild. The vulnerability was added to CISA's Known Exploited Vulnerabilities Catalog on August 20, 2026.

Who Is Targeting This

No confirmed threat actor attribution is available. Reported (research-inferred): no public attribution has been identified; reporting discusses CVE-2026-72529 alongside CVE-2026-72530 as a potential TrueConf Server takeover vector, but does not name specific threat groups or ransomware operators.

What To Do

Treat this as an urgent patching priority and apply the vendor-provided TrueConf Server security update as soon as it is available. CISA Known Exploited Vulnerabilities requirements direct federal civilian executive branch agencies to patch by September 10, 2026, or apply mitigations. Until remediation is complete, restrict TCP port 4307 access to only trusted administrative networks and block Internet exposure. Review TrueConf Server and host logs for unexpected connections to port 4307, unauthorized script execution, unusual child processes spawned by the TrueConf Server service, and unexplained configuration changes. No specific detection signatures or threat actor indicators are publicly confirmed.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →