Our takeCISA added two TrueConf Server CVEs to KEV, confirming active exploitation in versions before 5.3.9, 5.4.9 and 5.5.5. Patch immediately if you run it yourself.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — Security leader:Update TrueConf Server to 5.3.9, 5.4.9 or 5.5.5+ immediately; CISA reports active exploitation of CVE-2026-72529 and CVE-2026-72530.
What this means for you — Lean IT orgs:If you run TrueConf Server, update it today to version 5.3.9, 5.4.9 or 5.5.5 or newer. CISA says attackers are already using these flaws.
What this means for you — MSP:Check every client running TrueConf Server and push updates to at least 5.3.9 / 5.4.9 / 5.5.5; CISA has listed active exploitation.
What this means for you — Researcher:CISA added CVE-2026-72529 and CVE-2026-72530 to KEV based on confirmed exploitation in TrueConf Server 5.3.x–5.5.x; patch to the fixed releases.