Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-72530
TrueConf TrueConf Server — A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.…
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N H P N N H H H 9.5 .0169 76.2 YES
AFFECTED
Product Versions Fixed
TrueConf Server unspecified —
TIMELINE
Aug 10 Reserved by Kaspersky
Aug 19 EXPLOIT PUBLISHED — CVE-2026-72530 (TrueConf Server). Public exploit reference added.
Aug 19 Published (CNA: Kaspersky)
Aug 20 ADDED TO KEV — CVE-2026-72530 (TrueConf Server). Remediation due September 3, 2026.
Aug 21 EXPLOIT PUBLISHED — CVE-2026-72530 (TrueConf Server). Public exploit reference added.
Sep 4 DUE DATE PASSED — CVE-2026-72530 (TrueConf Server). CISA remediation deadline was September 3, 2026; still in catalog.
Description
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
Lifecycle
Complete event history — 6 events, chronological
| Date | Event | Detail |
| August 10, 2026 | Reserved | Reserved by Kaspersky |
| August 19, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-72530 (TrueConf Server). Public exploit reference added. |
| August 19, 2026 | Published | Published (CNA: Kaspersky) |
| August 20, 2026 | KEV ADDED | ADDED TO KEV — CVE-2026-72530 (TrueConf Server). Remediation due September 3, 2026. |
| August 21, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-72530 (TrueConf Server). Public exploit reference added. |
| September 4, 2026 | DUE DATE PASSED | DUE DATE PASSED — CVE-2026-72530 (TrueConf Server). CISA remediation deadline was September 3, 2026; still in catalog. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| TrueConf | TrueConf Server | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-72530 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.