CVE-2026-72529
Pre-auth account takeover over TrueConf's client port 4307/TCP -> arbitrary command execution as a server account (CVSS 9.3)
- Severity
- critical
- Affected product
- TrueConf Server
- Affected versions
- TrueConf Server < 5.5.6
- CISA KEV
- Listed as a known exploited vulnerability
- Added to NewScan
- 2026-08-21
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the TrueConf Server appliance and reports this CVE when the detected version falls inside the affected range below.
The second half of the 2026-08-21 TrueConf KEV pair, same Head Mare / PhantomCore intrusion set, same advisory, same affected range and same 4307/TCP vector. Kept as a SEPARATE row rather than folded into CVE-2026-72530's note (the Bouncy Castle consolidation) because both are independently KEV-listed: a consolidated row would report one CVE id where CISA lists two, and the KEV id is what an assessor and a BOD 26-04 deadline are keyed on. Both rows share `lt 5.5.6`, so an unpatched install yields one finding naming both - build_known_vuln_finding groups by component.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →