EXPOSURES › CVE-2026-72530
CVE-2026-72530
HIGH ⌖ ON CISA KEV · EXPLOITEDTrueConf Server allows remote code execution via a code injection flaw on port 4307/TCP, enabling attackers to break isolation and execute arbitrary code on the host.
A code injection vulnerability in TrueConf Server lets remote attackers bypass isolation on port 4307/TCP to execute arbitrary code on the host system. DIB organizations must patch this immediately as it enables full system compromise, violates CMMC/NIST 800-171 controls around remote access and system integrity, and exposes sensitive data to ransomware or espionage. Organizations should verify patch levels on all TrueConf deployments and restrict access to port 4307/TCP until patched.
Shame score — A remote code execution flaw in a widely deployed conferencing server that allows attackers to break isolation and execute arbitrary code represents a severe, avoidable security failure that could lead to data breaches and system compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.