Knox CVE Database
/
CVE-2026-72530
Critical
9.5

CVE-2026-72530: TrueConf Server Code Injection Vulnerability

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

Added to the CISA KEV catalog:
August 20, 2026

Overview

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

Vulnerability details

Affected vendor
TrueConf
Affected product
Server
Weakness type (CWE)
CWE-94

CVE-2026-72530 is a code injection (CWE-94) sandbox escape in TrueConf Server's isolated execution environment. The server runs received scripts inside an isolated environment that is intended to block direct access to operating system functions. Due to improper management of code generation within that environment, a crafted script can break out of the sandbox boundary and execute arbitrary commands on the underlying host OS. All TrueConf Server versions before 5.3, 5.3.x before 5.3.9, 5.4.x before 5.4.9, and 5.5.x before 5.5.5 are affected on both Windows and Linux.


This flaw is reachable only after an attacker first achieves code execution inside the isolated environment. In the observed attacks by the Head Mare APT group, that initial foothold was obtained through a companion missing-authentication flaw on port 4307/TCP, which is open by default per product documentation. Once inside the sandbox, the attacker submits a specially crafted script that exploits the improper code-generation controls to escape the isolation boundary. The result is arbitrary code execution on the host with NT AUTHORITY\SYSTEM privileges, which the attackers used to deploy web shells at the path ...\public\js\locale.php, harvest credentials via LSASS memory dumps, install the PhantomCore and PhantomGraph backdoors, and replace legitimate TrueConf Client installers with trojanized versions.

Severity and impact

9.5
Critical
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Check the TrueConf Server web root for unexpected modifications to locale.php (path: ...\public\js\locale.php). A file-integrity alert on this path that does not correspond to a vendor update is a direct indicator of post-exploitation web shell placement documented in observed attacks.
  • Audit Windows registry for the persistence key HKEY_CURRENT_USER\Software\Classes\CLSID\{0340F119-A598-4ed9-B0AC-6F6A12D3E755}\InprocServer32 pointing to an unexpected DLL path. This key was created by the PhantomCore backdoor and has no legitimate TrueConf association.
  • Monitor for Windows services named SysExcSvc or SysReadSvc, or DLLs with those names registered as services. These are PhantomGraph backdoor components installed via Base64-encoded PowerShell in the observed attack chain and should not be present on any TrueConf Server host.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
September 3, 2026

Additional hardening

  • Upgrade TrueConf Server to version 5.3.9 (for the 5.3.x line), 5.4.9 (for the 5.4.x line), or 5.5.5 (for the 5.5.x line). See the vendor advisory in References for build-level boundaries within each release line.
  • Restrict network access to port 4307/TCP to explicitly authorized management hosts only. Because this port is open by default and was the entry point in observed attacks, firewall or host-based rules blocking untrusted sources reduce the attack surface for the full exploit chain.
  • If port 4307/TCP cannot be immediately restricted, conduct a forensic triage per CISA's Forensics Triage Requirements (see References): check locale.php integrity, scan for the PhantomCore registry persistence key, and inspect installed Windows services for SysExcSvc and SysReadSvc before treating the host as clean.
  • Run an up-to-date antivirus scan across the TrueConf Server host and verify the integrity of any TrueConf Client installer packages distributed from the server, as attackers replaced legitimate installers with backdoored versions in confirmed incidents.

Key dates

Published (NVD)
August 19, 2026
Added to CISA KEV
August 20, 2026
Remediation deadline
September 3, 2026
Last updated
August 21, 2026

References

Frequently asked questions

Does CVE-2026-72530 affect my FedRAMP authorization?

If TrueConf Server runs inside your authorization boundary, yes. CVE-2026-72530 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, carrying a remediation deadline of September 3, 2026. For a FedRAMP-authorized service, an unpatched KEV within the boundary is an assessor finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it as a deficiency.

How does Knox help me handle CVE-2026-72530?

Knox does not patch TrueConf Server on your behalf. Remediation is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus continuous compliance monitoring and audit-artifact coverage to help you document the fix ahead of your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-72530. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you the lead time to act before a finding becomes a formal deficiency.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-72530 isn't remediated by September 3, 2026?

Missing the September 3, 2026 deadline turns CVE-2026-72530 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization in good standing and the agency relationship intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting