high Known exploited

CVE-2026-72530

TrueConf Server Code Injection Vulnerability

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

Published
Aug 19, 2026
CVSS
9.0
Vendor
TrueConf
Product
Server
CISA due date
2026-09-03
Source
merged

References

Check your website: Korisec scans for exposed services, weak TLS, missing headers, and WordPress plugin risks. Run a free scan or start a trial.

← Back to CVE Tracker · Official record: cve.org