CISA warning about TrueConf Server vulnerabilities being actively exploited, with cybersecurity servers and security alert graphics

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two actively exploited vulnerabilities in TrueConf Server to its Known Exploited Vulnerabilities (KEV) catalog, putting renewed attention on security risks affecting organizations that use the self-hosted communications platform.

The two vulnerabilities, tracked as CVE-2026-72529 and CVE-2026-72530, were added to the CISA catalog on August 20, 2026.

Both vulnerabilities affect certain older versions of TrueConf Server and can potentially allow unauthorized remote attackers to execute scripts or arbitrary code on affected systems.

The development is particularly important for U.S. federal agencies because vulnerabilities added to the KEV catalog are prioritized for remediation under federal cybersecurity requirements. It is also relevant to businesses, universities and other organizations that operate their own TrueConf Server infrastructure.

What Happened With TrueConf Server?

TrueConf Server is a self-hosted video conferencing and communications platform. Unlike cloud-based services where much of the infrastructure is managed by the provider, self-hosted deployments require organizations to maintain and secure their own servers.

Security researchers identified two serious vulnerabilities affecting TrueConf Server.

CVE-2026-72529 is a missing-authentication vulnerability affecting a critical function. According to vulnerability records, a remote unauthorized attacker with network access to TCP port 4307 could execute an arbitrary script through an undocumented function.

The vulnerability has a CVSS 3.1 score of 9.8, placing it in the critical severity category.

CVE-2026-72530 is a code-injection vulnerability involving a breakout from an isolated environment. A remote attacker could use a specially crafted script to escape the isolated environment and execute arbitrary code on the host system.

It carries a CVSS 3.1 score of 9.0, also classified as critical.

Both vulnerabilities were assigned by Kaspersky, which reported that the issues were discovered in early August and subsequently disclosed through its security advisories.

CISA Adds Both Vulnerabilities to Its KEV Catalog

CISA's Known Exploited Vulnerabilities catalog is designed to identify security flaws that have evidence of exploitation in real-world attacks.

The addition of the TrueConf vulnerabilities means they are no longer simply theoretical security concerns.

CISA's KEV records identify both vulnerabilities as exploited vulnerabilities and provide remediation guidance for affected organizations.

For federal civilian agencies, KEV entries are particularly significant because agencies are expected to prioritize remediation according to CISA's vulnerability-management requirements.

The broader message for private organizations is also important: a vulnerability with confirmed exploitation deserves attention even when an organization has many other software updates competing for limited security resources.

Which TrueConf Server Versions Are Affected?

The vulnerabilities affect older versions of TrueConf Server.

According to security advisory information, affected versions include:

  • TrueConf Server versions earlier than 5.3.9
  • 5.4.x versions earlier than 5.4.9
  • 5.5.x versions earlier than 5.5.5
  • Earlier versions before the listed supported branches are also affected

TrueConf's security information identifies 5.3.9, 5.4.9 and 5.5.5 as the relevant fixed releases.

Organizations should check the exact version installed on their servers rather than assuming that every TrueConf installation is vulnerable.

What Is CVE-2026-72529?

CVE-2026-72529 involves missing authentication for a critical function.

The vulnerability allows a remote unauthorized attacker with network access to port 4307/TCP to call an undocumented function and execute an arbitrary script.

The vulnerability is rated Critical, with a CVSS 3.1 score of 9.8.

The combination of remote network access, no required privileges and high potential impact makes the vulnerability particularly serious for exposed systems.

Organizations operating TrueConf Server should therefore determine whether the affected service is reachable from networks that should not have access to it.

CISA's KEV record lists August 23, 2026 as the remediation due date for this vulnerability for applicable federal agencies.

What Is CVE-2026-72530?

CVE-2026-72530 addresses a different but related security weakness.

The vulnerability involves a code-injection problem that can allow an attacker to break out of an isolated environment and execute arbitrary code on the host system.

The vulnerability has a CVSS 3.1 score of 9.0 and a CVSS 4.0 score of 9.5.

Its potential impact is significant because escaping an application's isolated environment can provide an attacker with greater control over the underlying host.

CISA added this vulnerability to the KEV catalog on August 20 and lists September 3, 2026 as the remediation due date for applicable federal agencies.

Why Are These Vulnerabilities So Serious?

The biggest concern is the combination of remote access, critical severity and confirmed exploitation.

A software vulnerability can be dangerous even before attackers begin using it. Once exploitation is observed, however, organizations have less time to treat the issue as a routine update.

The TrueConf vulnerabilities also affect communication infrastructure.

Video conferencing and collaboration servers can contain information about users, meetings, organizational configuration and network infrastructure. Depending on how a system is deployed, a compromised server could potentially become a starting point for additional unauthorized activity.

That does not mean every organization using TrueConf has been compromised.

It means administrators should determine whether they are running an affected version and whether the server has been exposed to potentially untrusted networks.

Organizations Should Check Their TrueConf Installations

Organizations using TrueConf Server should begin by identifying their installed version.

If the server falls within an affected version range, administrators should follow the vendor's security guidance and update to a fixed release.

Security teams should also review network exposure and determine whether TCP port 4307 is accessible from untrusted networks.

Where appropriate, organizations should monitor server logs and other security telemetry for unusual activity.

If there are indications that an affected server may already have been compromised, administrators should not rely solely on installing the update.

They should investigate the system for possible indicators of compromise and consider whether credentials or other connected systems could have been affected.

The Importance of Patch Management

The TrueConf incident is another reminder that patch management remains one of the most important parts of enterprise cybersecurity.

Organizations often operate hundreds or thousands of applications and systems. Not every vulnerability can be fixed immediately.

That makes prioritization essential.

CISA's KEV catalog provides one useful signal because it focuses attention on vulnerabilities that have already been exploited.

Security teams can combine KEV information with their own asset inventories, network exposure and threat intelligence to determine which systems require immediate action.

For organizations operating internet-facing servers, this type of prioritization can make the difference between addressing a vulnerability before an incident and investigating it afterward.

Does This Mean TrueConf Users Have Been Hacked?

No.

The CISA designation does not mean that every organization using TrueConf Server has been compromised.

It means the vulnerabilities have been added to a catalog of known exploited vulnerabilities.

Organizations need to evaluate their own systems, versions and network exposure.

Administrators should also avoid assuming that an absence of obvious warning signs means a vulnerable server was never targeted.

Where there is a reason to suspect compromise, a proper security investigation should be performed.

What Businesses Should Learn From the Warning

Although CISA's remediation requirements primarily concern U.S. federal agencies, the underlying security lesson applies much more broadly.

Businesses and other organizations that operate self-hosted software have to monitor vendor security advisories and maintain a regular patching process.

Waiting until a vulnerability becomes a major news story can leave organizations with less time to respond.

The TrueConf vulnerabilities also demonstrate why security teams should pay attention to vulnerabilities that move into CISA's KEV catalog.

A critical vulnerability with known exploitation deserves a different level of urgency than a vulnerability that has never been observed in attacks.

What Happens Next?

The immediate priority for affected organizations is to identify vulnerable TrueConf Server installations and apply the appropriate security updates.

Federal agencies will also have to follow the applicable CISA remediation requirements associated with the KEV entries.

For private-sector organizations, the CISA warning provides another opportunity to review software inventories and ensure that critical collaboration infrastructure is not running outdated versions.

The incident could also encourage organizations to review their broader exposure to self-hosted communication platforms.

As video conferencing and digital collaboration remain essential to businesses and government agencies, securing the infrastructure behind these services will continue to be an important part of enterprise cybersecurity.

For organizations running TrueConf Server, the message is straightforward: check the version, review exposure and apply the vendor's security updates if the installation is affected.


Frequently Asked Questions

What are the TrueConf Server vulnerabilities?

The vulnerabilities are CVE-2026-72529 and CVE-2026-72530. Both affect certain older versions of TrueConf Server and have been added to CISA's Known Exploited Vulnerabilities catalog.

Why did CISA add the vulnerabilities to its KEV catalog?

CISA added the vulnerabilities because they have evidence of exploitation. The KEV catalog helps organizations prioritize vulnerabilities that pose an immediate security risk.

Which TrueConf Server versions are affected?

Affected releases include versions earlier than 5.3.9, 5.4.x versions earlier than 5.4.9 and 5.5.x versions earlier than 5.5.5.

What are the fixed TrueConf Server versions?

The relevant fixed releases identified in the security advisories are 5.3.9, 5.4.9 and 5.5.5.

What should TrueConf Server administrators do?

Administrators should check their installed version, review the vendor's security advisory and update affected installations to an appropriate fixed release.

Does the CISA warning mean every TrueConf user has been hacked?

No. The KEV designation means the vulnerabilities have been exploited, not that every TrueConf installation has been compromised.

Why is the CISA KEV catalog important?

The KEV catalog helps organizations prioritize vulnerabilities that are known to have been exploited in real-world attacks.

Verified sources 

CISA Known Exploited Vulnerabilities information

Canadian Centre for Cyber Security — TrueConf Advisory

CVE-2026-72529 details

CVE-2026-72530 details

TrueConf Security Vulnerabilities, Fixes and Advisories