THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities related to TrueConf Server to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities are: CVE-2026-72529, with a CVSS score of 9.3, involves missing authentication for critical functions allowing unauthorized code execution; and CVE-2026-72530, with a CVSS score of 9.5, is a sandbox escape vulnerability that permits attackers to execute arbitrary code on the host machine.
Both vulnerabilities affect multiple versions of TrueConf Server. CISA mandates federal agencies to address these vulnerabilities by specified deadlines to secure their networks.