Skip to content
COOEY

EXPOSURES › CVE-2026-72529

CVE-2026-72529

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-08-20 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-72529 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrce

TrueConf Server lacks authentication on a critical function, allowing remote attackers to execute arbitrary scripts via port 4307/TCP.

TrueConf Server's missing authentication for a critical function enables remote attackers to execute arbitrary scripts without authorization. DIB organizations must ensure all TrueConf Server instances are patched immediately, as this vulnerability is actively exploited in the wild and poses a severe risk to system integrity and data confidentiality. Failure to patch exposes the organization to potential data breaches and compliance violations under NIST 800-171.

Shame score — The vendor shipped a product with a critical authentication bypass that allows remote code execution, and the vulnerability is actively exploited in the wild, indicating severe negligence in patch management and security design.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.