CVE-2026-72530: TrueConf Server Code Injection Vulnerability
Summary
TrueConf Server has a code injection vulnerability that allows remote attackers to execute arbitrary code on the host system. This could be achieved by using a specially crafted script via port 4307/TCP to break out of an isolated environment. The vulnerability requires immediate mitigation according to vendor instructions and CISA guidance.
IFF Assessment
A code injection vulnerability allowing arbitrary code execution by remote attackers poses a significant threat to system security and data integrity.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 03, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should prioritize patching or mitigating this vulnerability in TrueConf Server deployments, especially those exposed to the network on port 4307/TCP. The ability for unauthenticated remote attackers to execute arbitrary code is a severe risk that could lead to complete system compromise or ransomware deployment.