securityaffairs.com 8/21/2026, 9:30:40 AM · external

CISA adds TrueConf Server CVEs to KEV, urges urgent patching

CISA adds TrueConf Server CVEs to KEV, urges urgent patching
Developing story vulnerability 8 articles tracked
TrueConf Server authentication bypass and code injection flaws (CVE-2026-72529, CVE-2026-72530) exploited
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities related to TrueConf Server to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities are: CVE-2026-72529, with a CVSS score of 9.3, involves missing authentication for critical functions allowing unauthorized code execution; and CVE-2026-72530, with a CVSS score of 9.5, is a sandbox escape vulnerability that permits attackers to execute arbitrary code on the host machine.

Both vulnerabilities affect multiple versions of TrueConf Server. CISA mandates federal agencies to address these vulnerabilities by specified deadlines to secure their networks.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline