TL;DR π
- TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
- Highest CVSS: 9.0 (Critical).
- Listed in CISA KEV (2026-08-20) β this is being exploited in the wild.
- Check the advisory for fixed releases β remediation detail is in the vendor link below.
- CVEs: CVE-2026-72530.
What it is
CVE-2026-72530 is a code injection vulnerability in TrueConf Server. An attacker with network access to port 4307/TCP can submit a specially crafted script that breaks out of the server’s isolated execution environment and runs arbitrary code on the underlying host.