CISA Flags Two Actively Exploited TrueConf Server Vulnerabilities
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new security flaws affecting TrueConf Server to its Known Exploited Vulnerabilities (KEV) Catalog, confirming that attackers are actively exploiting them. The vulnerabilities, CVE-2026-72529 and CVE-2026-72530, involve a missing authentication check on a critical function and a code injection flaw respectively, both of which could allow attackers to gain unauthorised access or control over affected systems.
While the KEV Catalog primarily drives remediation requirements for US federal agencies under Binding Operational Directive 26-04, it also serves as a valuable early-warning list for any organisation using the affected software. Vulnerabilities included in the catalog are considered high risk precisely because real-world attacks have already been observed, not just theoretical proof-of-concept exploits.
Australian small and medium businesses using TrueConf Server for video conferencing or collaboration should check whether they run an affected version and apply vendor patches as soon as possible. Even businesses without direct exposure should treat KEV Catalog listings as a useful signal for prioritising patching efforts across their own software estate.