Government Advisory

CISA Flags Two Actively Exploited TrueConf Server Vulnerabilities

CISA · 20 Aug 2026
Key Takeaway If your business uses TrueConf Server, check for security updates immediately and treat any CISA KEV Catalog listing as a priority patching signal.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new security flaws affecting TrueConf Server to its Known Exploited Vulnerabilities (KEV) Catalog, confirming that attackers are actively exploiting them. The vulnerabilities, CVE-2026-72529 and CVE-2026-72530, involve a missing authentication check on a critical function and a code injection flaw respectively, both of which could allow attackers to gain unauthorised access or control over affected systems.

While the KEV Catalog primarily drives remediation requirements for US federal agencies under Binding Operational Directive 26-04, it also serves as a valuable early-warning list for any organisation using the affected software. Vulnerabilities included in the catalog are considered high risk precisely because real-world attacks have already been observed, not just theoretical proof-of-concept exploits.

Australian small and medium businesses using TrueConf Server for video conferencing or collaboration should check whether they run an affected version and apply vendor patches as soon as possible. Even businesses without direct exposure should treat KEV Catalog listings as a useful signal for prioritising patching efforts across their own software estate.

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.