Knox CVE Database
/
CVE-2026-72529
Critical
9.3

CVE-2026-72529: TrueConf Server Missing Authentication for Critical Function Vulnerability

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

Added to the CISA KEV catalog:
August 20, 2026

Overview

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Vulnerability details

Affected vendor
TrueConf
Affected product
Server
Weakness type (CWE)
CWE-306

TrueConf Server exposes an undocumented function on port 4307/TCP that requires no authentication before use. This is a CWE-306 (Missing Authentication for Critical Function) flaw: a critical server capability is reachable by any network peer without credentials, session tokens, or any other identity verification. Port 4307/TCP is open by default per product documentation, meaning any host with network access to the server can reach this function. Affected versions span all releases before 5.3, the 5.3.X line before 5.3.9, the 5.4.X line before 5.4.9, and the 5.5.X line before 5.5.5.


An attacker with network access to port 4307/TCP sends a crafted call to the undocumented server function, supplying a malicious script as the payload. The server executes that script in an isolated scripting environment without requiring any credentials. Kaspersky researchers attributed active exploitation to the Head Mare APT group, which chained this flaw with a second vulnerability (KLCERT-26-058) to escape the isolated environment and achieve arbitrary code execution as NT AUTHORITY\SYSTEM. Post-exploitation activity included placing a web shell at the path ...\public\js\locale.php, accessing the TrueConf database, and replacing legitimate TrueConf Client installers with versions carrying the PhantomCore backdoor.

Severity and impact

9.3
Critical
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Audit network connections to port 4307/TCP: connections originating from hosts outside the expected TrueConf peer list, or from any external address, are anomalous and warrant immediate investigation given the unauthenticated exposure.
  • Check the TrueConf web root for unexpected modifications to locale.php (path: ...\public\js\locale.php); presence of a web shell at this path is a confirmed post-exploitation indicator documented in Head Mare campaign reporting.
  • On Windows hosts running TrueConf Server, look for new services named SysExcSvc or SysReadSvc, or for the registry key HKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32, both of which are persistence indicators tied to the PhantomGraph and PhantomCore backdoors deployed in confirmed exploitation.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 23, 2026

Additional hardening

  • Upgrade TrueConf Server to version 5.3.9 (for the 5.3.X line), 5.4.9 (for the 5.4.X line), or 5.5.5 (for the 5.5.X line); all releases before these boundaries are affected, including all versions before 5.3. See References for the vendor advisory.
  • Restrict network access to port 4307/TCP at the perimeter and host-based firewall to only the specific hosts that require TrueConf server communication; this port should not be reachable from untrusted networks or the public internet.
  • Conduct a full scan for Head Mare indicators of compromise as documented in Kaspersky ICS CERT reporting, including the web shell path, PhantomCore and PhantomGraph artifacts, and the registry persistence key; if any are found, treat all local accounts as compromised and rotate credentials.
  • If patching cannot be applied immediately, consider taking the TrueConf Server offline or isolating it behind strict network controls until the update is applied, given active exploitation by an APT group and the unauthenticated nature of the attack path.

Key dates

Published (NVD)
August 19, 2026
Added to CISA KEV
August 20, 2026
Remediation deadline
August 23, 2026
Last updated
August 21, 2026

References

Frequently asked questions

Does CVE-2026-72529 affect my FedRAMP authorization?

If TrueConf Server runs inside your authorization boundary, CVE-2026-72529 creates a direct FedRAMP compliance obligation. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 23, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it before that date or formally document a mitigation, or your sponsoring agency will raise it.

How does Knox help me handle CVE-2026-72529?

Knox does not patch TrueConf Server on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-72529 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary to carry out that remediation in, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work is yours to execute; maintaining a defensible compliance posture while you execute it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-72529 surfaces, exposure appears during continuous monitoring rather than only when an assessor flags it at scheduled review time, giving you more time to act before it becomes a formal finding.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-72529 isn't remediated by August 23, 2026?

If CVE-2026-72529 remains unpatched after August 23, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating by the deadline keeps your authorization standing intact and the agency relationship on solid ground.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting