Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [cve, kev, code-injection, trueconf, actively-exploited] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, government] ยท au_impact: true

CVE-2026-72530 โ€” TrueConf Server Code Injection

CVE-2026-72530 is a code-injection vulnerability affecting TrueConf Server. CISA added it to the Known Exploited Vulnerabilities (KEV) catalogue on 20 August 2026, alongside CVE-2026-72529, marking the third consecutive day of KEV additions.

Details

Field Value
CVE CVE-2026-72530
Product TrueConf Server
Type Code injection
Exploitation Confirmed in the wild (KEV-added 2026-08-20)
CVSS Not stated in the KEV entry
Remediation 14-day federal remediation clock under BOD 26-04

Impact

The two TrueConf Server flaws (CVE-2026-72529 and CVE-2026-72530) reflect a criminal ecosystem continuing to add internet-facing collaboration and conferencing products to its attack list. Any operator of TrueConf Server should treat both CVEs as actively exploited and apply vendor fixes without delay.

Source