CVE-2026-72529 · Moderate · CISA KEV

TrueConf Server: Critical Function Missing Authentication Allows Remote Script Execution

Threat Engine Auto-Feed · data current as of 2026-08-21

A critical vulnerability in TrueConf Server (CVE-2026-72529) allows remote, unauthenticated attackers to execute arbitrary scripts via port 4307/TCP. This flaw is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, posing a significant risk to affected organizations.

  • CVSS:
  • EPSS percentile: 0.21051
  • Exploitation pressure: 38/100 (Moderate)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 21th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

This vulnerability is due to a critical function in TrueConf Server lacking proper authentication. This means that an attacker can interact with a sensitive part of the software without needing to prove their identity, allowing them to perform unauthorized actions.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations using TrueConf Server for internal or external communication, especially those in financial services or technology sectors.
  • Enterprises with TrueConf Server instances exposed to untrusted networks or the internet.

Misconfigurations that escalate it

  • TrueConf Server instances directly exposed to the internet without proper network segmentation or access controls.
  • Lack of network monitoring for unusual activity on port 4307/TCP.

High-impact scenarios

  • Remote code execution leading to full system compromise of the TrueConf Server.
  • Initial access for financially motivated threat actors (e.g., FIN7, LockBit affiliates, APT38) or state-sponsored groups (e.g., APT29) to pivot into the internal network.
  • Data exfiltration, service disruption, or deployment of ransomware.

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor network traffic for suspicious activity on TrueConf Server instances, particularly on port 4307/TCP.
  • Look for unauthorized script execution attempts or unusual process creation on TrueConf Server hosts.
  • Review TrueConf Server logs for any unauthenticated access to critical functions.

Contain

  • Isolate affected TrueConf Server instances from the network if compromise is suspected.
  • Block external access to TrueConf Server on port 4307/TCP until a patch can be applied.

Patch

  • Apply the latest security updates and patches from TrueConf as soon as they become available to address CVE-2026-72529.

Frontier verdict — Moderate

Immediate patching is critical due to active exploitation in the wild and the potential for remote unauthenticated arbitrary script execution.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.