CVE-2026-72529
TrueConf TrueConf Server, trueconf server
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
- CVSS
- 9.3
- EPSS
- - - percentile
- CISA KEV
- Listed
- Published
- 2026.08.20