TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.
TrueConf Server exposes an undocumented function on port 4307/TCP that requires no authentication before use. This is a CWE-306 (Missing Authentication for Critical Function) flaw: a critical server capability is reachable by any network peer without credentials, session tokens, or any other identity verification. Port 4307/TCP is open by default per product documentation, meaning any host with network access to the server can reach this function. Affected versions span all releases before 5.3, the 5.3.X line before 5.3.9, the 5.4.X line before 5.4.9, and the 5.5.X line before 5.5.5.
An attacker with network access to port 4307/TCP sends a crafted call to the undocumented server function, supplying a malicious script as the payload. The server executes that script in an isolated scripting environment without requiring any credentials. Kaspersky researchers attributed active exploitation to the Head Mare APT group, which chained this flaw with a second vulnerability (KLCERT-26-058) to escape the isolated environment and achieve arbitrary code execution as NT AUTHORITY\SYSTEM. Post-exploitation activity included placing a web shell at the path ...\public\js\locale.php, accessing the TrueConf database, and replacing legitimate TrueConf Client installers with versions carrying the PhantomCore backdoor.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If TrueConf Server runs inside your authorization boundary, CVE-2026-72529 creates a direct FedRAMP compliance obligation. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 23, 2026. An unpatched KEV inside your boundary is an assessor finding. You must either remediate it before that date or formally document a mitigation, or your sponsoring agency will raise it.
Knox does not patch TrueConf Server on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2026-72529 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary to carry out that remediation in, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work is yours to execute; maintaining a defensible compliance posture while you execute it is not something you manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-72529 surfaces, exposure appears during continuous monitoring rather than only when an assessor flags it at scheduled review time, giving you more time to act before it becomes a formal finding.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
If CVE-2026-72529 remains unpatched after August 23, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating by the deadline keeps your authorization standing intact and the agency relationship on solid ground.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)









