CVE-2026-72530
Summary
| CVE | CVE-2026-72530 |
|---|---|
| State | PUBLISHED |
| Assigner | Kaspersky |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-19 17:21:01 UTC |
| Updated | 2026-08-20 04:17:05 UTC |
| Description | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. |
Risk And Classification
Primary CVSS: v4.0 9.5 CRITICAL from [email protected]
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-94 | CWE-94 CWE-94: Code Injection
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 9.5 | CRITICAL | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/C... |
| 4.0 | CNA | CVSS | 9.5 | CRITICAL | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
| 3.1 | [email protected] | Secondary | 9 | CRITICAL | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9 | CRITICAL | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | TrueConf | TrueConf Server | affected * 5.3 custom | Windows, Linux |
| CNA | TrueConf | TrueConf Server | affected 5.3 5.3.9 custom | Windows, Linux |
| CNA | TrueConf | TrueConf Server | affected 5.4 5.4.9 custom | Windows, Linux |
| CNA | TrueConf | TrueConf Server | affected 5.5 5.5.5 custom | Windows, Linux |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ics-cert.kaspersky.com/advisories/2026/08/11/trueconf-server-breakout-from-isolated-... | [email protected] | ics-cert.kaspersky.com | |
| securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | securelist.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Vyacheslav Kopeytsev from Kaspersky ICS CERT (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-08-03T00:00:00.000Z | Issue discovered by Kaspersky ICS CERT and reported to TrueConf |
| CNA | 2026-08-04T00:00:00.000Z | Issue confirmed by TrueConf |
| CNA | 2026-08-07T00:00:00.000Z | Advisory published by Kaspersky ICS CERT |
Solutions
CNA: Update TrueConf server to versions 5.3.9, 5.4.9 or 5.5.5.
Workarounds
CNA: Perform a full check with anti-virus software that has up-to-date anti-virus databases and software modules.
CNA: Conduct a scan for indicators of compromise. In the event of detecting indicators of compromise, change passwords for accounts that may have been compromised and contact Kaspersky ICS CERT at [email protected] for further instructions and assistance in investigating the incident.