Our takeCISA added two TrueConf Server CVEs to KEV, confirming active exploitation in versions before 5.3.9, 5.4.9 and 5.5.5. Patch immediately if you run it yourself.Cyber Resilience desk
Sources (1)
- bleeping · bleeping
What this means for you — Security leader:Federal agencies must apply the TrueConf Server patches for the two KEV-listed CVEs immediately. All other organizations running self-hosted TrueConf Server should patch to 5.3.9, 5.4.9 or 5.5.5 (or later) as soon as possible.
What this means for you — Lean IT orgs:If you run your own TrueConf Server for video calls or chat, update it to the latest version right away. Most small teams using a hosted service instead can ignore this.
What this means for you — MSP:Check every client running self-hosted TrueConf Server and patch to at least 5.3.9 / 5.4.9 / 5.5.5 immediately; clients using a cloud-hosted comms platform are not affected.
What this means for you — Researcher:CISA added two TrueConf Server RCEs to KEV, confirming active exploitation in versions before 5.3.9, 5.4.9 and 5.5.5.