What has changed

CISA added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities catalogue on 20 August, saying the decision was based on evidence of active exploitation. Both affect TrueConf Server. The first is a missing-authentication weakness that can allow an unauthorised remote attacker with network access to the service to execute a script. The second can allow code already running in the product's isolated environment to escape it and execute on the host operating system.

The two weaknesses are related operationally but should not be blurred into one claim. Kaspersky ICS CERT describes the second as higher-complexity and says it may require several attempts, while the authentication weakness is rated low-complexity. CISA's listing confirms exploitation of both CVEs, but the cited sources do not say that every exposed server is compromised or associate the activity with ransomware.

[1][2][3]

Which servers are affected

Kaspersky ICS CERT lists TrueConf Server for Windows and Linux in all releases before 5.3, in the 5.3 branch before 5.3.9, in 5.4 before 5.4.9, and in 5.5 before 5.5.5. Its advisories identify 5.3.9, 5.4.9 and 5.5.5 as the corresponding fixed releases for both vulnerabilities. Administrators should follow the supported destination for their installed branch rather than treating those three numbers as interchangeable packages.

Both advisories require network access to the affected service on TCP port 4307. That condition helps teams establish exposure, but filtering the port is not presented by the cited advisories as a substitute for updating. CISA's federal remediation deadlines apply to US civilian agencies, not UK businesses; the KEV listing is useful here as verified exploitation evidence for prioritisation.

[1][2][3]

What defenders should do

Inventory production, standby, test and supplier-operated TrueConf Server installations. Record the operating system, complete version, service owner, internet or untrusted-network reachability and any filtering around the affected service. Confirm the version through an authorised administrative route; a product banner or unauthenticated external check is not enough to establish patch state.

Update affected systems to 5.3.9, 5.4.9 or 5.5.5 according to their supported branch, following TrueConf's current upgrade instructions. Back up necessary configuration, plan rollback and test conferencing, authentication, integrations, recording, monitoring and resilience afterwards. Keep network restrictions proportionate, but do not describe them as the vendor fix.

For servers that were reachable from untrusted networks while affected, preserve relevant application, operating-system, authentication, network and administrative logs before broad changes. Review them proportionately using the organisation's incident process. Kaspersky ICS CERT also recommends an up-to-date antivirus check and a review for the indicators in its linked threat alert; detection results are evidence to investigate, not proof that every affected system was attacked.

  • Locate every production, standby, test and supplier-run TrueConf Server.
  • Capture the exact branch, build, operating system and network reachability.
  • Move affected servers to the appropriate fixed release.
  • Test conferencing, identity, integrations, monitoring and recovery afterwards.
  • Preserve useful evidence and investigate only evidence-backed signs of compromise.
[1][2][3]

The Beekeeper view

A conferencing server sits where identity, internal conversations and network services meet. Once exploitation is verified, the sensible response is prompt, controlled remediation without converting a catalogue entry into an unsupported breach declaration.

The lasting control is a service record that joins the exact build to its owner, network paths, supplier, update route and evidence sources. That turns the next urgent advisory into a bounded maintenance decision instead of a hunt for an inherited server nobody quite owns.

[1][2][3]
Find every TrueConf Server, confirm its complete branch and build, and move affected installations to 5.3.9, 5.4.9 or 5.5.5 as appropriate while preserving evidence where exposure warrants review.

Primary sources

  1. CISA Adds Two Known Exploited Vulnerabilities to Catalog — US Cybersecurity and Infrastructure Security Agency, 20 August 2026
  2. KLCERT-26-057: TrueConf Server. Missing authentication for critical function — Kaspersky ICS CERT, 11 August 2026
  3. KLCERT-26-058: TrueConf Server. Breakout from isolated environment — Kaspersky ICS CERT, 11 August 2026

Beekeeper field notes summarise primary advisories for a UK business audience. Always follow the affected vendor’s current instructions for your exact product and version.