type: cve ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [cve, kev, missing-auth, rce, trueconf, actively-exploited] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, government] ยท au_impact: true
CVE-2026-72529 โ TrueConf Server Missing Authentication
CVE-2026-72529 is a missing-authentication vulnerability for critical functions in TrueConf Server. CISA added it to the Known Exploited Vulnerabilities (KEV) catalogue on 20 August 2026, alongside CVE-2026-72530, after corroborating exploitation in the wild.
Details
| Field | Value |
|---|---|
| CVE | CVE-2026-72529 |
| Product | TrueConf Server |
| Type | Missing authentication for critical function |
| Exploitation | Confirmed in the wild (KEV-added 2026-08-20) |
| CVSS | Not stated in the KEV entry |
| Remediation | 14-day federal remediation clock under BOD 26-04 |
Impact
TrueConf is a self-hosted video-conferencing product used by government and enterprise estates. With confirmed exploitation, unpatched internet-facing instances of TrueConf Server are exposed to unauthorised access to critical functions. The KEV addition also starts the two-week remediation clock for federal agencies and should be treated as an urgent patching trigger by all operators of the platform.
Sources
- CISA โ Adds Two Known Exploited Vulnerabilities to Catalog โ 2026-08-20