Critical severity9.0CISA KEVNVD Advisory· Published Aug 19, 2026· Updated Aug 21, 2026
CVE-2026-72530
CVE-2026-72530
Description
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
3- securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/nvdExploitThird Party Advisory
- ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-breakout-from-isolated-environment/nvdThird Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
4- Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using itThe Register Security · Aug 21, 2026
- CISA Urges Immediate Patching of Exploited TrueConf VulnerabilitiesSecurityWeek · Aug 21, 2026
- Trueconf: 2 Actively-Exploited Flaws Added to CISA KEVVypr Intelligence · Aug 20, 2026
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA Alerts