[KEV] CVE-2026-72530 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2026-72530 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2026-72530 is a remote code injection and sandbox-escape vulnerability in TrueConf Server that is reachable over TCP port 4307.
Technical Detail
An unauthenticated attacker with network access to port 4307/TCP can submit a specially crafted script to trigger code injection within TrueConf Server. The flaw can allow the attacker to escape the product's isolated execution environment and execute arbitrary code on the underlying host system. Successful exploitation results in remote code execution with the privileges of the affected TrueConf Server process.
Exploitation Status
Exploit maturity is assessed as Operational, indicating that exploitation capability is usable in real-world operations rather than being limited to a theoretical issue or public proof of concept. CISA has confirmed active exploitation in the wild, and added this vulnerability to the Known Exploited Vulnerabilities Catalog on August 20, 2026.
Who Is Targeting This
Reported (research-inferred): No public attribution is available. The supplied reporting notes confirmed exploitation but does not identify specific threat actors, ATT&CK groups, ransomware operations, origin, or motivation.
What To Do
Prioritize deployment of the vendor-provided fix or updated TrueConf Server version when available. Restrict access to TCP port 4307 to trusted administrative networks and explicitly authorized systems; do not expose the service directly to the internet where avoidable. Monitor TrueConf Server and host telemetry for unexpected script execution, child processes spawned by the TrueConf Server service, and unusual outbound connections from the server. As this is KEV-listed, patch by the CISA-specified remediation date or apply mitigations where patching is not immediately possible.