type: cve ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [cve, kev, code-injection, trueconf, actively-exploited] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, government] ยท au_impact: true
CVE-2026-72530 โ TrueConf Server Code Injection
CVE-2026-72530 is a code-injection vulnerability affecting TrueConf Server. CISA added it to the Known Exploited Vulnerabilities (KEV) catalogue on 20 August 2026, alongside CVE-2026-72529, marking the third consecutive day of KEV additions.
Details
| Field | Value |
|---|---|
| CVE | CVE-2026-72530 |
| Product | TrueConf Server |
| Type | Code injection |
| Exploitation | Confirmed in the wild (KEV-added 2026-08-20) |
| CVSS | Not stated in the KEV entry |
| Remediation | 14-day federal remediation clock under BOD 26-04 |
Impact
The two TrueConf Server flaws (CVE-2026-72529 and CVE-2026-72530) reflect a criminal ecosystem continuing to add internet-facing collaboration and conferencing products to its attack list. Any operator of TrueConf Server should treat both CVEs as actively exploited and apply vendor fixes without delay.
Source
- CISA โ Adds Two Known Exploited Vulnerabilities to Catalog โ 2026-08-20