
CISA has added two critical vulnerabilities affecting TrueConf Server to its Known Exploited Vulnerabilities catalogue, warning that both are being actively exploited in the wild. The flaws were disclosed in a security advisory posted by the vendor and promptly logged by the agency on 20 August 2026. Administrators should treat the issue as urgent because remote attackers can gain full control without authentication.
The first flaw, tracked as CVE-2026-72529, carries a CVSS v3 score of 9.8 and results from a missing authentication check on TCP port 4307, letting an unauthenticated attacker run arbitrary scripts on the server. The second flaw, recorded as CVE-2026-72530, scores 9.5 and is a code injection issue that enables a remote user to break out of the application’s isolated environment and execute commands with the privileges of the TrueConf Server process. Details of the active exploitation chain, including the deployment of PhantomCore malware, are outlined in a recent analysis.
According to the incident record, the first exploitation attempts were seen on 20 August 2026 at 18:08 UTC, with the latest activity observed on 21 August 2026 at 02:03 UTC. During that window attackers used the flaws to install PhantomCore and establish footholds inside compromised networks. No specific threat actor has been publicly attributed to the activity, but the behaviour matches known post‑exploitation tooling used in similar campaigns. The short but intense observation period highlights how quickly the flaws are being leveraged once exposed.
Both vulnerabilities were added to the KEV catalogue on 20 August 2026 after confirmation that attackers are using them in the wild to install PhantomCore and maintain persistent access. The inclusion in the catalogue signals that exploitation is ongoing and poses a significant risk to any TrueConf Server deployment reachable from the internet or internal networks. Defenders should prioritise these flaws because they allow unauthenticated remote code execution with high impact scores.
Defenders should first identify any TrueConf Server instances listening on TCP port 4307 and consider restricting access to trusted networks or disabling the service if it is not required. Patches have been released for the affected lines, with updates to versions 5.3.9, 5.4.9 and 5.5.5 or later addressing both CVE‑2026‑72529 and CVE‑2026‑72530, as noted in the vendor’s security advisory. Administrators should also review the mitigation steps listed in the CISA KEV entries for CVE‑2026‑72529 and CVE‑2026‑72530.
Organisations should continue monitoring logs for unexpected script execution or outbound connections from TrueConf Server, enforce least privilege on service accounts, and ensure incident response playbooks cover the possibility of code execution via these flaws. Staying informed through the CISA alert that announced the KEV additions and checking the vendor’s blog for future advisories will help maintain resilience against similar threats.