CVE-2026-72530 – TrueConf Server
CVSS 9
CRITICAL
Zero Day – Immediate Deployment
“Actively exploited flaws can give remote attackers a direct path from exposed services to arbitrary code execution.”
TrueConf Server is affected by two actively exploited Critical vulnerabilities accessible through port 4307/TCP. CVE-2026-72529 has a CVSS score of 9.8, Critical severity and allows an unauthorized remote attacker to execute arbitrary scripts through an undocumented function. CVE-2026-72530 has a CVSS score of 9.0, Critical severity and allows an unauthorized remote attacker to escape the isolated environment and execute arbitrary code on the host.
The issues affect the specified TrueConf Server 5.3.x, 5.4.x, and 5.5.x releases and earlier versions.
Key Details
- Affected Product
- Trueconf Trueconf Server
- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-94
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.