LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 20, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 23, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-72529 to its Known Exploited Vulnerabilities catalog on Aug 20, 2026, with a federal patch deadline of Aug 23, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary…

CVE-2026-72529 is a missing-authentication weakness in TrueConf Server. An unauthorized remote attacker who can reach the product over the network on port 4307/TCP may be able to invoke a critical function and execute an arbitrary script. For organizations that run TrueConf Server—especially where that service is reachable beyond tightly controlled networks—this matters because authentication is the primary gate on powerful server-side actions; without it, exposure of that port can turn into remote code execution risk. Confirm affected builds, fixed releases, and exact scope only against the vendor advisory.

CISA’s required action direction is to apply mitigations per vendor instructions, align with BOD 26-04 risk-based update prioritization and forensics triage expectations, evaluate internet exposure of each asset, and discontinue use if mitigations are unavailable. Ransomware use is not documented in the provided facts.

How it works

This issue is classed as CWE-306: missing authentication for a critical function. In products of this type, certain administrative or server-side operations are meant to run only after the caller proves identity and authorization. When that check is absent or incomplete on a network-exposed interface, anyone who can speak the protocol to the listening service may trigger the function as if they were trusted.

Per the given summary, the abuse path is network access to TrueConf Server on port 4307/TCP by a remote unauthorized attacker, leading to arbitrary script execution. That implies the critical function is reachable without login (or equivalent) and that its parameters or handling allow scripted actions on the host or application context. Do not assume payload format, preconditions beyond network reachability to that port, or chaining details—those must be taken from the vendor advisory and your own lab validation. Defenders should treat unauthenticated reachability to the implicated service endpoint as the core enabling condition.

Am I affected? How to find it in your systems

TrueConf Server is collaboration/video-conferencing server software typically deployed on dedicated hosts or VMs in data centers, branch offices, or cloud VPCs, and sometimes published for remote users. Inventory every system that runs TrueConf Server: configuration management databases, software inventory agents, package/service lists, install directories, and listening-port surveys.

How to remediate

Patch first: apply the vendor-supplied update or mitigation package named in the TrueConf advisory for CVE-2026-72529, following their validated install and restart procedure. Verify the post-update build and that the service behaves as documented. Where CISA BOD 26-04 applies to your environment, prioritize by asset exposure and business criticality and complete any required forensics triage steps if compromise is suspected.

If you can't patch immediately

Reduce attack surface until the vendor fix is installed. Compensating controls do not replace the patch for a missing-authentication flaw on a critical function.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to full server compromise, lateral movement, and exposure of meeting data, recordings, directories, or credentials stored or accessible from the host. Ransomware use is not documented for this CVE in the facts provided, but unauthorized script execution still warrants treating internet-exposed or suspicious hosts as potentially breached: isolate, preserve volatile evidence, rotate secrets, and follow your incident response and CISA forensics triage expectations. As a routine hygiene step, users and admins can run a free exposure scan of their work email addresses against known breach datasets to see whether those identities already appear in unrelated leaks, then tighten passwords and MFA accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTrueConf · Server
WeaknessCWE-306
Added to CISA KEVAug 20, 2026
Federal patch deadlineAug 23, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities