Skip to content

CVE-2026-72530

TrueConf Server isolated environment breakout enables unauthenticated remote code execution (CVE-2026-72530)

Critical 9.5 KEV Published · Updated

TrueConf Server before 5.3.9 (5.3.x), before 5.4.9 (5.4.x) and before 5.5.5 (5.5.x) can be exploited over TCP 4307 by an unauthenticated attacker to escape an isolated environment and run code on the host. CISA KEV lists active exploitation. Apply the fixed builds.

What happened

TrueConf Server contains an isolated environment, but an attacker who can reach TCP port 4307 over the network may be able to send a specially crafted script that breaks out of that environment and executes arbitrary code on the host system. No credentials or user interaction are required, although the CVSS 4.0 vector records high attack complexity and additional attack requirements, so specific conditions need to be present. The score is 9.5, classified as critical, and the weakness is CWE-94.

CISA added CVE-2026-72530 to the Known Exploited Vulnerabilities catalog on 2026-08-20, with a due date of 2026-09-03. CISA KEV and CISA SSVC both record exploitation as active. Organisations should treat this as an exploited vulnerability rather than a theoretical risk.

Who is affected

TrueConf Server is affected in the following releases: versions before 5.3, 5.3 to before 5.3.9, 5.4 to before 5.4.9, and 5.5 to before 5.5.5. The server listens on TCP port 4307. Deployments where that port is reachable from untrusted networks are directly exposed to this issue.

Fixed versions are listed as TrueConf Server 5.3.9, TrueConf Server 5.4.9, and TrueConf Server 5.5.5.

What to do now

  1. Apply the relevant fixed release: TrueConf Server 5.3.9, TrueConf Server 5.4.9, or TrueConf Server 5.5.5, depending on your current branch.
  2. If patching must be delayed, restrict access to TCP 4307 at network boundaries and remove TrueConf Server from direct internet exposure.
  3. Follow CISA’s KEV required action: apply mitigations in accordance with vendor instructions, comply with BOD 26-04 prioritisation guidance and the Forensics Triage Requirements, and discontinue use of the product if mitigations are unavailable.

How to detect it

Identify every TrueConf Server in the estate and confirm whether TCP 4307 is reachable from the internet or other untrusted zones. Because successful exploitation results in arbitrary code execution on the host, servers that had or have this port exposed should be reviewed for unexplained processes or changes associated with the TrueConf service.

Beyond the patch

This is an unauthenticated, network-reachable code execution flaw in a communications server, and CISA KEV records active exploitation. Patching is the immediate priority, but the same exposure pattern will recur elsewhere. Managed Detection & Response (MDR) provides detection and containment around services that remain exposed, and an Incident Response Retainer gives priority access if an active incident is suspected. A Virtual CISO Services (vCISO) review can help identify and close exposed TrueConf deployments before they are targeted.

Affected and fixed versions

ProductAffectedFixed in
TrueConf Server– < 5.3
5.3 – < 5.3.9
5.4 – < 5.4.9
5.5 – < 5.5.5
5.3.9
5.4.9
5.5.5

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.