Skip to content
Threat Feed
critical threat exploited

Active Exploitation of TrueConf Server Vulnerabilities

TrueConf Server versions 5.3.x, 5.4.x, and 5.5.x are vulnerable to CVE-2026-72529 and CVE-2026-72530, which are currently being exploited in the wild according to CISA KEV.

CVE search metadata

CVE search record: CVE-2026-72529. Severity: critical. CVSS: 9.8. KEV: no. Product: TrueConf Server 5.3, TrueConf Server 5.4, TrueConf Server 5.5. Brief: Active Exploitation of TrueConf Server Vulnerabilities. Brief link: https://feed.craftedsignal.io/briefs/2026-08-trueconf-vulnerabilities/

CVE search record: CVE-2026-72530. Severity: critical. CVSS: 9.0. KEV: no. Product: TrueConf Server 5.3, TrueConf Server 5.4, TrueConf Server 5.5. Brief: Active Exploitation of TrueConf Server Vulnerabilities. Brief link: https://feed.craftedsignal.io/briefs/2026-08-trueconf-vulnerabilities/

TrueConf has issued a security advisory regarding multiple vulnerabilities affecting the TrueConf Server software suite. The affected versions include 5.3.x (prior to 5.3.9), 5.4.x (prior to 5.4.9), and 5.5.x (prior to 5.5.5). On August 20, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added these vulnerabilities, tracked as CVE-2026-72529 and CVE-2026-72530, to its Known Exploited Vulnerabilities (KEV) catalog. This designation confirms that threat actors are actively exploiting these flaws in real-world environments. Organizations running TrueConf Server are urged to update to the latest available versions immediately to mitigate the risk of unauthorized access or exploitation.

Impact

Successful exploitation of these vulnerabilities allows unauthorized actors to compromise TrueConf Server instances, which may lead to full system takeover, unauthorized access to internal communications, or data exfiltration. Given the inclusion of these CVEs in the CISA KEV, all internet-facing TrueConf Server instances are at immediate risk of compromise.

Recommendation

  • Immediately audit all internet-facing TrueConf Server instances to identify affected versions (5.3.x < 5.3.9, 5.4.x < 5.4.9, 5.5.x < 5.5.5).
  • Apply the vendor-provided patches as detailed in the TrueConf Security Advisories page.
  • Prioritize patching any TrueConf Server instances accessible from the public internet.
  • Review network access logs for unusual patterns originating from or directed toward TrueConf Server infrastructure.

Immediate actions

Patch TrueConf Server instances to the versions specified in the security advisory

IT Operations 24h