CISA Adds Two Known Exploited Vulnerabilities to Catalog

Summary

CISA has added two new vulnerabilities, CVE-2026-72529 and CVE-2026-72530, both related to TrueConf Server, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. The article also references Binding Operational Directive (BOD) 26-04, which mandates federal agencies to prioritize patching vulnerabilities listed in the KEV Catalog.

IFF Assessment

FOE

The addition of new, actively exploited vulnerabilities to CISA's KEV catalog represents an increased risk to organizations, particularly federal agencies, as these flaws are being leveraged by malicious actors.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: August 23, 2026. Known ransomware use: Unknown.

Defender Context

Organizations, especially federal agencies, should immediately review their environments for TrueConf Server and prioritize patching these newly identified vulnerabilities. The inclusion in the KEV catalog signifies active exploitation, meaning attackers are likely already targeting these weaknesses.

Read Full Story →