← Browse

CVE-2026-72529

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
1.6%
74.0th percentile
CISA KEV
Listed
Added 2026-08-20 · patch by 2026-08-23
Weakness / dates
CWE-306
Published 2026-08-19 · modified 2026-08-21

Description

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Affected

trueconf

References

Official: NVD · CVE.org