Threat intel / CVE tracker
CVE-2026-72529
Critical KEV · actively exploited PoC availableCVSS base score
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HA remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Vendor
trueconf
Product
trueconf server
Affected
trueconf trueconf server
Weakness
CWE-306 · Auth bypass
Published
Aug 19, 2026
Last modified
Aug 21, 2026
CVSS version
v3.1
Views
4
// References & exploits
https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/Third Party Advisoryhttps://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/PoCThird Party Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72529US Government Resource