CVE-2026-72530 – TrueConf Server

CVSS 9 CRITICAL Zero Day – Immediate Deployment

“Actively exploited flaws can give remote attackers a direct path from exposed services to arbitrary code execution.”

TrueConf Server is affected by two actively exploited Critical vulnerabilities accessible through port 4307/TCP. CVE-2026-72529 has a CVSS score of 9.8, Critical severity and allows an unauthorized remote attacker to execute arbitrary scripts through an undocumented function. CVE-2026-72530 has a CVSS score of 9.0, Critical severity and allows an unauthorized remote attacker to escape the isolated environment and execute arbitrary code on the host.

The issues affect the specified TrueConf Server 5.3.x, 5.4.x, and 5.5.x releases and earlier versions.

Key Details

Affected Product
Trueconf Trueconf Server
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
CWE Classification
CWE-94
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.