ZeroDayAlert

CVE-2026-72530: TrueConf Server Code Injection Vulnerability

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

TrueConf Server Added to KEV 2026-08-20 Federal due 2026-09-03 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

TrueConf Server is affected by a code injection vulnerability accessible via port 4307/TCP. An unauthenticated attacker on the network can craft a script that breaks out of the product's isolation and run arbitrary code on the host machine. The record does not specify which versions of TrueConf Server are vulnerable, nor does it detail whether this affects on-premises deployments, cloud-hosted instances, or both.

How to check whether this touches you

  • Inventory whether TrueConf Server is deployed in your environment, and in what capacity (on-premises, cloud-hosted, or hybrid).
  • Check whether port 4307/TCP is reachable from an untrusted network segment or the internet. Use network scanning or firewall rule audits to establish this.
  • Establish the current TrueConf Server version running on each instance; check the product's administrative console or documentation for version discovery methods.
  • Query your logs for any inbound connections to port 4307/TCP, particularly from unexpected sources, to establish baseline exposure.

What to do

  1. Immediately consult TrueConf's vendor guidance and apply any mitigations or patches they have published. This is your primary remediation path.
  2. If patching is not immediately feasible, restrict network access to port 4307/TCP at the firewall level; limit it to trusted hosts or networks only.
  3. Enable logging on port 4307/TCP and monitor for suspicious connection attempts or payloads. Retain logs according to your data retention policy.
  4. Review your compliance obligations under CISA's BOD 26-04 Prioritizing Security Updates Based on Risk. If you are a federal agency or contractor, the due date for remediation is 3 September 2026.
  5. If the product is cloud-hosted and the vendor cannot provide mitigations, evaluate discontinuation of the service in accordance with BOD 26-04 guidance.
  6. Escalate to your security operations centre and change advisory board if TrueConf Server is critical to your operations and patching will require scheduled downtime.

If you find you were exposed

Exploitation typically occurs before public disclosure, so assume any permitted inbound connection to port 4307/TCP could have been exploited. Retrieve your network and application logs for the widest retention window available and search for connections to that port, particularly successful ones. If your logs show traffic to port 4307/TCP from untrusted sources, engage your incident response team to inspect the host for unauthorised processes, lateral movement, and evidence of privilege escalation. Ransomware campaign involvement is not yet known, but treat any code execution risk as a potential stepping stone to broader compromise.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-72530 is being exploited. It cannot tell you whether Server is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →