type: incident ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [incident, kev, cisa, exploited-in-the-wild, trueconf] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: true
CISA Adds Two TrueConf Server CVEs to Known Exploited Vulnerabilities
CISA added TrueConf Server CVE-2026-72529 (missing authentication for critical function) and CVE-2026-72530 (code injection) to the Known Exploited Vulnerabilities catalogue on 20 August 2026, the third consecutive day of KEV additions.
Key Facts
| Field | Detail |
|---|---|
| KVEs added | CVE-2026-72529 (missing authentication), CVE-2026-72530 (code injection) |
| Date | 2026-08-20 |
| Products | TrueConf Server |
| Context | Third consecutive day of KEV additions |
| Remediation | 14-day federal remediation clock under BOD 26-04 |
Impact
The pair reflect a criminal ecosystem continuing to add internet-facing collaboration and conferencing products to its attack list. The additions start the two-week federal remediation clock under BOD 26-04 and extend the same urgency horizon to any operator of TrueConf. For AU/NZ organisations, the week's KEV cadence reinforces the Essential Eight patching conversation and the two-week federal remediation expectation for government entities and ASD-partnered organisations.
Source
- CISA โ Adds Two Known Exploited Vulnerabilities to Catalog โ 2026-08-20