CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability

Summary

TrueConf Server has a critical vulnerability where a missing authentication flaw allows remote attackers to execute arbitrary scripts. This impacts network access via port 4307/TCP. Federal agencies must apply mitigations by August 23, 2026, according to CISA guidance.

IFF Assessment

FOE

The identified vulnerability allows for remote, unauthorized script execution, posing a direct threat to system integrity and confidentiality.

Severity

9.8 Critical

CISA KEV: Listed as actively exploited. Federal patch due: August 23, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in TrueConf Server is critical as it allows remote code execution without authentication, posing a significant risk to organizations using the product. Defenders should prioritize patching and monitoring for any signs of exploitation on port 4307/TCP.

Read Full Story →