CVE-2026-72529 is a missing authentication for critical function vulnerability affecting TrueConf Server. A remote, unauthenticated attacker with network access via port 4307/TCP can exploit this vulnerability to execute arbitrary scripts. The vulnerability is classified as critical due to its unauthenticated remote exploitation potential. It is tracked by CISA and listed in advisories from Kaspersky ICS-CERT and TrueConf's own security blog. The vulnerability is subject to CISA's BOD 26-04 directive, which prioritizes security updates based on risk. Forensics triage requirements are also outlined under the BOD 26-04 implementation guidance. Organizations running TrueConf Server are urged to apply available security fixes immediately.
4307/TCP