Organizations should apply updates to TrueConf Server to address CVE-2026-72529 and CVE-2026-72530. CISA BOD 26-04 establishes expectations for checking whether threat actors compromised systems before the patch was applied. Prioritize remediation on publicly exposed assets.
Quick answers
What is CVE-2026-72530?
Organizations should apply updates to TrueConf Server to address CVE-2026-72529 and CVE-2026-72530. CISA BOD 26-04 establishes expectations for checking whether threat actors compromised systems before the patch was applied. Prioritize remediation on publicly exposed assets.
How severe is CVE-2026-72530?
high
Is CVE-2026-72530 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-72530 be mitigated?
Organizations should apply updates to TrueConf Server to address CVE-2026-72529 and CVE-2026-72530. CISA BOD 26-04 establishes expectations for checking whether threat actors compromised systems before the patch was applied. Prioritize remediation on publicly exposed assets.
CVSS
—
Vendor
TrueConf
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
TrueConf Server
Mitigation
Organizations should apply updates to TrueConf Server to address CVE-2026-72529 and CVE-2026-72530. CISA BOD 26-04 establishes expectations for checking whether threat actors compromised systems before the patch was applied. Prioritize remediation on publicly exposed assets.
The Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities affecting TrueConf Server to its Known Exploited Vulnerabilities (KEV) Catalog. CVE-2026-72529 involves missing authentication for a critical function, and CVE-2026-72530 involves code injection. Both were added based on evidence of active exploitation and pose significant risks to federal and organizational networks.