TrueConf Server Code Injection Vulnerability: CVE-2026-72530
- Severity
- HIGH
- Affected component
- trueconf (npm)
- Patched version
- Not yet available
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to execute arbitrary code on the host system. Users of TrueConf Server are affected.
What happened
TrueConf Server, a self-hosted communications platform, has been found to contain a critical code injection vulnerability. This vulnerability, tracked as CVE-2026-72530, allows an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that this vulnerability is being actively exploited in the wild.
The vulnerability was first flagged on August 20, 2026, and confirmed later the same day. CISA has ordered U.S. federal agencies to prioritize patching this vulnerability. TrueConf Server is designed for secure corporate messaging and video conferencing, operating inside an organization's local network (LAN).
What to do about it
- Upgrade to the latest version of TrueConf Server.
- Ensure network access to port 4307/TCP is restricted.
- Monitor the primary sources for updates on the vulnerability and any available patches.
How 0Day would have caught this
trueconf is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using TrueConf Server, you are affected by this vulnerability.
What should I do right now?
Upgrade to the latest version of TrueConf Server and ensure network access to port 4307/TCP is restricted.
Has this been exploited in the wild?
Yes, this vulnerability is being actively exploited in the wild.
Sources
- CISA orders feds to patch actively exploited TrueConf Server flaws
- [CISA KEV] CVE-2026-72529 — TrueConf Server
- [CISA KEV] CVE-2026-72530 — TrueConf Server
- CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
- Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it