LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-72530: TrueConf Server Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 20, 2026
Elevated⚠ Actively exploited (CISA KEV)
Elevated
Severity
Active
CISA KEV
No
Ransomware use
Sep 3, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-72530 to its Known Exploited Vulnerabilities catalog on Aug 20, 2026, with a federal patch deadline of Sep 3, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the…

CVE-2026-72530 is a code injection vulnerability in TrueConf Server. An unauthorized remote attacker who can reach the product over the network on port 4307/TCP may send a specially crafted script that breaks out of an isolated environment and runs arbitrary code on the host. That elevates a network-accessible service flaw into full host compromise risk for collaboration infrastructure, so IT and security teams should treat exposure of this service as high priority until patched or otherwise controlled. Confirm all product-specific details against the vendor advisory.

How it works

This issue is classified as CWE-94 (Improper Control of Generation of Code, or “code injection”). In this class of flaw, the application accepts input that influences code the system later executes, without sufficient isolation or validation. Per the public summary, TrueConf Server can be abused by an unauthorized attacker with network access to port 4307/TCP: a specially crafted script is used to escape the intended isolated environment and execute arbitrary code on the underlying host.

Technical readers should assume the attack path is remote and unauthenticated relative to normal user login, limited by reachability of that port and whatever network path exists to the server. Exact request format, script contents, and internal components involved are not detailed in the provided facts; do not invent exploit steps. Treat any successful breakout as equivalent to remote code execution on the host running TrueConf Server, with follow-on risk of persistence, lateral movement, or data access depending on the host’s privileges and network position.

Am I affected? How to find it in your systems

TrueConf Server is typically deployed as on-premises or privately hosted video conferencing / collaboration server software. Inventory anywhere your organization runs TrueConf Server—data centers, branch servers, DMZ or edge hosts, and cloud VMs you manage—especially instances that accept connections on TCP 4307.

How to remediate

Patch first. Apply the vendor-supplied update or mitigation package for TrueConf Server exactly as named in the official advisory, and verify the service build after upgrade. Align prioritization with CISA’s direction: apply mitigations per vendor instructions, follow BOD 26-04 guidance on risk-based security updates and forensics triage expectations, and for cloud-delivered instances follow applicable BOD 26-04 cloud guidance—or discontinue use if mitigations are unavailable.

If you can't patch immediately

Use compensating controls until the vendor fix is installed. These do not replace patching for a code-injection / isolation-breakout issue.

If your data may have been exposed

Actively exploited remote code execution flaws on collaboration servers can lead to host takeover and follow-on data access or broader compromise. If this service was reachable on 4307/TCP while unpatched, investigate those hosts for intrusion, rotate credentials and secrets that resided on or were accessible from them, and follow your incident response process. You can run a free exposure scan of your email addresses against known breach datasets to see whether associated accounts already appear in public breach collections, and then strengthen those identities accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTrueConf · Server
WeaknessCWE-94
Added to CISA KEVAug 20, 2026
Federal patch deadlineSep 3, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities