Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5424 articles · 195693 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-72529KEVEXPLOITEDPATCHED
trueconf · trueconf server

CVE-2026-72529: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4

Description

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Affected Products

VendorProductVersions
trueconftrueconf server*, 5.3, 5.4, 5.5

References

  • https://ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-missing-authentication-for-critical-function/(third-party-advisory)

Related News (2 articles)

Tier B
CCCS Canada4h ago
TrueConf security advisory (AV26-835)
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-72529 | TrueConf Server up to 5.2/5.3.8/5.4.8/5.5.4 improper authorization
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
5.35.3.95.4.95.5.5
CWECWE-306
PublishedAug 19, 2026
Trending Score139🔥
Source articles2
Independent2
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (1)

CRITICALCVE-2026-72530EXPKEV
CVE-2026-72530: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4
Trending: 129

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 19, 2026
Added to CISA KEV
Aug 19, 2026
Discovered by ZDM
Aug 19, 2026
Actively Exploited
Aug 20, 2026
Patch Available
Aug 20, 2026