CVE-2026-72529 is a critical missing-authentication flaw in TrueConf Server that allows a remote, unauthenticated attacker to execute arbitrary scripts by calling an undocumented function over TCP port 4307. This is a server-side vulnerability in internet-facing video conferencing infrastructure, actively exploited in the wild by the Head Mare threat actor group and listed in CISA KEV.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-08-19
Added to CISA KEV: 2026-08-20 1 DAY BETWEEN CVE AND KEV
CVE-2026-72529 is a critical vulnerability affecting TrueConf Server that arises from missing authentication for an undocumented function. By sending specially crafted requests to the server's TCP port 4307, a remote, unauthenticated attacker can execute arbitrary scripts on the host system. This vulnerability is significant because it allows for full system compromise, posing a severe risk to the confidentiality, integrity, and availability of affected organizations' video conferencing infrastructure.
An unauthenticated attacker with access to the TrueConf Server port 4307/TCP can trigger an undocumented function that lets them execute arbitrary scripts. Because the function lacks authentication checks, the attacker can run any commands on the host, potentially gaining full control and compromisi…
CVE-2026-72529 Detail Description A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Kaspersky discovered that Head Mare attackers were using CVE-2026-72529 to gain initial access to TrueConf servers; the vulnerability enables ...
CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability; CVE-2026-72530 TrueConf Server Code Injection ...
🛡️We added TrueConf Server vulnerabilities CVE-2026-72529 & CVE-2026-72530 to our Known Exploited Vulnerabilities Catalog.