Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [incident, kev, cisa, exploited-in-the-wild, trueconf] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: true

CISA Adds Two TrueConf Server CVEs to Known Exploited Vulnerabilities

CISA added TrueConf Server CVE-2026-72529 (missing authentication for critical function) and CVE-2026-72530 (code injection) to the Known Exploited Vulnerabilities catalogue on 20 August 2026, the third consecutive day of KEV additions.

Key Facts

Field Detail
KVEs added CVE-2026-72529 (missing authentication), CVE-2026-72530 (code injection)
Date 2026-08-20
Products TrueConf Server
Context Third consecutive day of KEV additions
Remediation 14-day federal remediation clock under BOD 26-04

Impact

The pair reflect a criminal ecosystem continuing to add internet-facing collaboration and conferencing products to its attack list. The additions start the two-week federal remediation clock under BOD 26-04 and extend the same urgency horizon to any operator of TrueConf. For AU/NZ organisations, the week's KEV cadence reinforces the Essential Eight patching conversation and the two-week federal remediation expectation for government entities and ASD-partnered organisations.

Source