CVE-2026-72530 · Moderate · CISA KEV

TrueConf Server Code Injection: Remote Code Execution via Port 4307/TCP

Threat Engine Auto-Feed · data current as of 2026-08-21

A code injection vulnerability in TrueConf Server (CVE-2026-72530) allows an unauthorized remote attacker to execute arbitrary code on the host system. This vulnerability, listed in CISA KEV, indicates active exploitation in the wild. Exploitation requires network access to port 4307/TCP.

  • CVSS:
  • EPSS percentile: 0.27168
  • Exploitation pressure: 41/100 (Moderate)

Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 27th percentile. Threat × Vulnerability from public signals — impact depends on your environment.

Weakness —

This vulnerability involves a code injection flaw, where an attacker can supply malicious code as input to an application. The application then processes this input without proper validation or sanitization, leading to the execution of the attacker's code within the system's environment. In this case, it allows breaking out of an isolated environment.

Who's at risk

Exposure: unknown · Auth: unknown · unknown

Enterprise profiles most at risk

  • Organizations utilizing TrueConf Server for internal or external communication, especially those in Financial Services or Technology sectors, are at heightened risk.
  • Enterprises with publicly exposed TrueConf Server instances or internal networks where port 4307/TCP is accessible to untrusted sources.

Misconfigurations that escalate it

  • Lack of strict network segmentation that allows untrusted access to TrueConf Server on port 4307/TCP.
  • Insufficient monitoring of network traffic on port 4307/TCP for anomalous activity.

High-impact scenarios

  • An attacker with network access to port 4307/TCP could achieve remote code execution on the TrueConf Server host, leading to full system compromise.
  • Successful exploitation could allow an attacker to pivot further into the internal network, exfiltrate sensitive data, or deploy additional malware like ransomware.

Likely adversaries

  • FIN7 — Financial services (Assessed)
  • LockBit affiliates — Financial services (Assessed)
  • APT38 (Lazarus) — Financial services (Assessed)
  • APT29 (Cozy Bear) — Technology (Assessed)
  • Scattered Spider — Technology (Assessed)

What to do (defensive)

Detect

  • Monitor network traffic on TrueConf Server's port 4307/TCP for unusual connection attempts or malformed requests.
  • Implement host-based intrusion detection systems (HIDS) to detect unauthorized process execution or file modifications on TrueConf Server hosts.
  • Review TrueConf Server logs for any indications of unexpected script execution or environment breakouts.

Contain

  • Isolate TrueConf Server instances from critical network segments if immediate patching is not feasible.
  • Restrict network access to TrueConf Server's port 4307/TCP to only trusted internal IP addresses or necessary services.

Patch

  • Apply the latest security updates and patches provided by TrueConf for Server to address CVE-2026-72530 as soon as they become available.

Frontier verdict — Moderate

This is a high-priority vulnerability due to confirmed in-the-wild exploitation (CISA KEV) allowing remote code execution on TrueConf Server via network access.

For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.