CVE-2026-72529 · Moderate · CISA KEV
TrueConf Server: Critical Function Missing Authentication Allows Remote Script Execution
Threat Engine Auto-Feed · data current as of 2026-08-21
A critical vulnerability in TrueConf Server (CVE-2026-72529) allows remote, unauthenticated attackers to execute arbitrary scripts via port 4307/TCP. This flaw is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, posing a significant risk to affected organizations.
- CVSS:
- EPSS percentile: 0.21051
- Exploitation pressure: 38/100 (Moderate)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 21th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
This vulnerability is due to a critical function in TrueConf Server lacking proper authentication. This means that an attacker can interact with a sensitive part of the software without needing to prove their identity, allowing them to perform unauthorized actions.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations using TrueConf Server for internal or external communication, especially those in financial services or technology sectors.
- Enterprises with TrueConf Server instances exposed to untrusted networks or the internet.
Misconfigurations that escalate it
- TrueConf Server instances directly exposed to the internet without proper network segmentation or access controls.
- Lack of network monitoring for unusual activity on port 4307/TCP.
High-impact scenarios
- Remote code execution leading to full system compromise of the TrueConf Server.
- Initial access for financially motivated threat actors (e.g., FIN7, LockBit affiliates, APT38) or state-sponsored groups (e.g., APT29) to pivot into the internal network.
- Data exfiltration, service disruption, or deployment of ransomware.
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor network traffic for suspicious activity on TrueConf Server instances, particularly on port 4307/TCP.
- Look for unauthorized script execution attempts or unusual process creation on TrueConf Server hosts.
- Review TrueConf Server logs for any unauthenticated access to critical functions.
Contain
- Isolate affected TrueConf Server instances from the network if compromise is suspected.
- Block external access to TrueConf Server on port 4307/TCP until a patch can be applied.
Patch
- Apply the latest security updates and patches from TrueConf as soon as they become available to address CVE-2026-72529.
Frontier verdict — Moderate
Immediate patching is critical due to active exploitation in the wild and the potential for remote unauthenticated arbitrary script execution.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.