NPM · AUGUST 2026 · CONFIRMED

TrueConf Server Code Injection Vulnerability: CVE-2026-72530

Severity
HIGH
Affected component
trueconf (npm)
Patched version
Not yet available
CVE-2026-72530

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to execute arbitrary code on the host system. Users of TrueConf Server are affected.

What happened

TrueConf Server, a self-hosted communications platform, has been found to contain a critical code injection vulnerability. This vulnerability, tracked as CVE-2026-72530, allows an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that this vulnerability is being actively exploited in the wild.

The vulnerability was first flagged on August 20, 2026, and confirmed later the same day. CISA has ordered U.S. federal agencies to prioritize patching this vulnerability. TrueConf Server is designed for secure corporate messaging and video conferencing, operating inside an organization's local network (LAN).

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If trueconf is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using TrueConf Server, you are affected by this vulnerability.

What should I do right now?

Upgrade to the latest version of TrueConf Server and ensure network access to port 4307/TCP is restricted.

Has this been exploited in the wild?

Yes, this vulnerability is being actively exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats