← Terug naar overzicht

CVE-2026-72530 is a code injection vulnerability affecting TrueConf Server that allows an unauthorized remote attacker with network access via port 4307/TCP to execute arbitrary code on the host system. The attacker can use a specially crafted script to break out of the server's isolated environment and gain access to the underlying host. This vulnerability does not require authentication, making it particularly dangerous for exposed deployments. The issue has been documented by Kaspersky ICS-CERT and is tracked by CISA, with fixes and advisories published by TrueConf. The vulnerability falls under CISA's BOD 26-04 directive, which prioritizes security updates based on risk, and forensic triage requirements have been outlined. Organizations running TrueConf Server are urged to apply available security fixes immediately.

Affected products

  • TrueConf Server

Related CVE's

  • CVE-2026-72530

Categories

  • Enterprise Applications
  • Network Infrastructure
  • Zero-Day Vulnerabilities