Skip to content
COOEY

EXPOSURES › CVE-2026-72530

CVE-2026-72530

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-08-20 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-72530 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wild

TrueConf Server allows remote code execution via a code injection flaw on port 4307/TCP, enabling attackers to break isolation and execute arbitrary code on the host.

A code injection vulnerability in TrueConf Server lets remote attackers bypass isolation on port 4307/TCP to execute arbitrary code on the host system. DIB organizations must patch this immediately as it enables full system compromise, violates CMMC/NIST 800-171 controls around remote access and system integrity, and exposes sensitive data to ransomware or espionage. Organizations should verify patch levels on all TrueConf deployments and restrict access to port 4307/TCP until patched.

Shame score — A remote code execution flaw in a widely deployed conferencing server that allows attackers to break isolation and execute arbitrary code represents a severe, avoidable security failure that could lead to data breaches and system compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.