Cyber Resilience
← All news
Claimed

CISA orders feds to patch actively exploited TrueConf Server flaws

Our takeCISA added two TrueConf Server CVEs to KEV, confirming active exploitation in versions before 5.3.9, 5.4.9 and 5.5.5. Patch immediately if you run it yourself.
Sources (1)
What this means for you — Security leader:Federal agencies must apply the TrueConf Server patches for the two KEV-listed CVEs immediately. All other organizations running self-hosted TrueConf Server should patch to 5.3.9, 5.4.9 or 5.5.5 (or later) as soon as possible.
What this means for you — Lean IT orgs:If you run your own TrueConf Server for video calls or chat, update it to the latest version right away. Most small teams using a hosted service instead can ignore this.
What this means for you — MSP:Check every client running self-hosted TrueConf Server and patch to at least 5.3.9 / 5.4.9 / 5.5.5 immediately; clients using a cloud-hosted comms platform are not affected.
What this means for you — Researcher:CISA added two TrueConf Server RCEs to KEV, confirming active exploitation in versions before 5.3.9, 5.4.9 and 5.5.5.