- Sources: Kaspersky ICS CERT KLCERT-26-057, CISA KEV catalog
- Summary: CISA added two TrueConf Server flaws to the known exploited vulnerabilities catalog on the same day. CVE-2026-72529 is a missing authentication for a critical function, CWE-306, reachable without authentication over port 4307/TCP, with a remediation due date of 2026-08-23. CVE-2026-72530 is a code injection allowing a breakout from the isolated environment over the same port, with a due date of 2026-09-03. The Kaspersky ICS CERT advisory KLCERT-26-057, published 2026-08-11, lists all versions before 5.3, 5.3.x before 5.3.9, 5.4.x before 5.4.9, and 5.5.x before 5.5.5 as affected, fixed in 5.3.9, 5.4.9, and 5.5.5, and attributes exploitation to the Head Mare group delivering PhantomCore malware.
- Why it matters: Exploitation is unauthenticated and reported as active, the fix is an upgrade within each supported branch, and blocking port 4307/TCP at the network edge is the control available to anyone who cannot upgrade today.
- Follow-up: Track whether TrueConf publishes a per-CVE advisory, since the catalog entry points only at a general advisories page.
send feedback on this story