CVE-2026-72530 is a critical unauthenticated code injection vulnerability in TrueConf Server that allows a remote attacker with network access to TCP port 4307 to break out of an isolated environment and execute arbitrary code on the host. The flaw requires no authentication or user interaction and is confirmed to be actively exploited in the wild (CISA KEV listed). This is a textbook T1190 case delivering direct server-side RCE.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2026-08-19
Added to CISA KEV: 2026-08-20 1 DAY BETWEEN CVE AND KEV
CVE-2026-72530 is a critical code injection vulnerability affecting TrueConf Server that allows a remote, unauthenticated attacker to escape an isolated environment and execute arbitrary code on the underlying host system. By sending a specially crafted script to the server via TCP port 4307, an attacker can gain unauthorized control over the system, making this a high-severity risk for any internet-facing deployment.
How severe is CVE-2026-72530? This vulnerability has a CVSS score of 9 out of 10, rated as Critical. Critical vulnerabilities can be exploited remotely without authentication and may lead to full system compromise, data theft, or malware installation. What Trueconf products are affected by CVE-2026-…
CVE-2026-72530 affects TrueConf · Server. Exploited in the wild (CISA KEV). A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions… Severity, affected software, exploitation status, patch guidance and references.
CVE-2026-72530 Detail Description A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code…