Cyber Resilience
← All news
Confirmed

TrueConf security advisory (AV26-835)

Our takeCISA added two TrueConf Server CVEs to KEV, confirming active exploitation in versions before 5.3.9, 5.4.9 and 5.5.5. Patch immediately if you run it yourself.
Sources (1)
What this means for you — Security leader:Update TrueConf Server to 5.3.9, 5.4.9 or 5.5.5+ immediately; CISA reports active exploitation of CVE-2026-72529 and CVE-2026-72530.
What this means for you — Lean IT orgs:If you run TrueConf Server, update it today to version 5.3.9, 5.4.9 or 5.5.5 or newer. CISA says attackers are already using these flaws.
What this means for you — MSP:Check every client running TrueConf Server and push updates to at least 5.3.9 / 5.4.9 / 5.5.5; CISA has listed active exploitation.
What this means for you — Researcher:CISA added CVE-2026-72529 and CVE-2026-72530 to KEV based on confirmed exploitation in TrueConf Server 5.3.x–5.5.x; patch to the fixed releases.