CVE-2026-72529
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TrueConf | TrueConf Server | * < 5.3 | affected |
| TrueConf | TrueConf Server | 5.3 < 5.3.9 | affected |
| TrueConf | TrueConf Server | 5.4 < 5.4.9 | affected |
| TrueConf | TrueConf Server | 5.5 < 5.5.5 | affected |
Weaknesses
- CWE-306: CWE-306: Missing Authentication for Critical Function
Workarounds
Perform a full check with anti-virus software that has up-to-date anti-virus databases and software modules. Conduct a scan for indicators of compromise. In the event of detecting indicators of compromise, change passwords for accounts that may have been compromised and contact Kaspersky ICS CERT at ics-cert@kaspersky.com for further instructions and assistance in investigating the incident.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: active
- Automatable: yes
- Technical Impact: total
Additional References
- https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-72529
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.