1. Executive summary
CVE-2026-72529 is a missing-authentication vulnerability in TrueConf Server that permits a remote, unauthorised attacker with network access to port 4307/TCP to invoke an undocumented function and execute an arbitrary script. Affected releases include 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier versions. The verified reference rates the vulnerability CVSS 9.3 CRITICAL, with EPSS 0%, and states that it is NOT in CISA KEV. The supplied NVD change history nevertheless records CISA SSVC exploitation as active and references the KEV catalogue; this conflicts with the verified reference, so Adverse Trace does not treat KEV listing or exploitation as confirmed. EMEA financial institutions operating an affected, network-reachable server should immediately restrict port 4307/TCP and obtain the vendor-prescribed remediation; the supplied material does not establish compromise, ransomware use or confirmed actor attribution.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The supplied facts also do not establish an affected client deployment, incident or service impact sufficient to map an item-specific UK NIS 2018 duty.
3. Technical analysis & attack chain
Authoritative status: CVSS 9.3 CRITICAL, EPSS 0%, and NOT in CISA KEV.
Confirmed vulnerability path
- Reachability: An attacker requires network access to a TrueConf Server over 4307/TCP. No application-layer protocol or alternative port is identified.
- Unauthenticated function invocation: The attacker calls an unspecified, undocumented function without authorisation. The weakness is classified as CWE-306: Missing Authentication for Critical Function.
- Script execution: Successful invocation permits execution of an arbitrary script. The source does not identify the script language, request format, function name, endpoint, execution identity or operating-system context.
- Potential effect: The verified severity is CVSS 9.3 CRITICAL. No observed compromise, payload, persistence mechanism, privilege escalation, command-and-control, lateral movement, data access or exfiltration is documented in the supplied material.
The NVD record identifies the following affected ranges:
- TrueConf Server 5.3.X through 5.3.9
- TrueConf Server 5.4.X through 5.4.9
- TrueConf Server 5.5.X through 5.5.5
- Earlier versions
These upper bounds must not be interpreted as confirmation that a subsequent release is fixed; the supplied sources do not identify a remediated version.
A related issue, CVE-2026-72530, concerns a specially crafted script escaping an isolated environment and executing arbitrary code on the host through the same port. The supplied material does not establish that CVE-2026-72529 and CVE-2026-72530 are chainable, share identical affected versions or are remediated by the same update.
Exploitation and attribution caveats
The verified reference states that CVE-2026-72529 is NOT in CISA KEV and has EPSS 0%. In contrast, the supplied NVD change history records a CISA-ADP transition from exploitation “none” to “active,” adds a KEV catalogue reference and includes KEV-style remediation language. This is a material metadata discrepancy; the verified state governs this advisory, and no KEV remediation deadline is asserted.
NVD references a Securelist report whose title names Head Mare and PhantomCore, but its substantive campaign evidence was not supplied. No MITRE actor profile appears in the verified reference data. Attribution to Head Mare is therefore unconfirmed and single-sourced; verify before enforcement.
4. Mitigation & containment
P1 — within 24 hours
- Inventory every TrueConf Server deployment and identify systems within the affected version ranges.
- Determine whether 4307/TCP is reachable from the internet, partner networks, user segments or other untrusted zones.
- Block 4307/TCP from untrusted sources at perimeter firewalls, security groups and internal segmentation controls. Where the service requires this port, allowlist only documented, necessary source addresses.
- If reachability cannot be constrained, isolate or temporarily discontinue the affected service until an official mitigation can be applied.
- Obtain and apply TrueConf’s official remediation instructions. The supplied material provides neither a fixed version nor a safe configuration change; do not infer a fixed release from the affected-version upper bounds.
- Where compromise is suspected, isolate the host and preserve TrueConf application logs, operating-system telemetry and firewall or flow records before remediation.
P2 — within 72 hours
- Review historical connections to 4307/TCP for access from sources not authorised by local policy.
- Correlate those connections with TrueConf telemetry for unauthenticated invocation of undocumented functionality and with host telemetry for subsequent script execution. The sources provide no endpoint, request signature or process name, so this review requires local baselining.
- Assess exposed TrueConf systems separately for CVE-2026-72530. Do not assume that containment or remediation for CVE-2026-72529 also addresses the related sandbox-escape issue.
- If unauthorised script execution is identified, initiate incident response, determine the execution context and rotate credentials or secrets accessible from the affected host.
P3 — within seven days
- Verify that no affected system remains reachable over 4307/TCP from an unauthorised network.
- Retest the remediated service to confirm that the undocumented function cannot be invoked without authentication.
- Record any temporary firewall or isolation measure as a compensating control and track it until vendor remediation is confirmed.
- Maintain monitoring for updated vendor guidance, a named fixed release, reconciled CISA/NVD exploitation status and validated indicators.
5. Indicators of compromise
No indicators of compromise available in the source material. The implied campaign context and any associated IOC set are single-sourced; verify before enforcement.
Behavioural indicators
| behaviour | where to observe | confidence |
|---|---|---|
| Network access to an affected TrueConf Server over 4307/TCP from a source not authorised by local policy | Firewall, network-flow or NDR telemetry | High for exposure identification; low as a standalone compromise signal |
| Invocation of an undocumented TrueConf function without an authenticated session | TrueConf application or request logs, if function and authentication state are recorded | High for the vulnerability mechanism; logging availability unknown |
| Arbitrary script execution following access over 4307/TCP | TrueConf application telemetry and host execution telemetry | High for the described mechanism; no process or script signature supplied |
These are expected behaviours derived from the vulnerability description, not observations from a documented intrusion.
6. Detection
Insufficient indicators to author detection rules.
CVE assessment
1 referenced CVE — 1 critical (CVSS ≥ 9.0)
| CVE | CVSS | Exploited | EPSS | Summary |
|---|---|---|---|---|
| CVE-2026-72529 | 9.3 Critical | — | 0% | A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5… |
7. Sources
- NIST NVD, “CVE-2026-72529,” 2026-08-19.
- NIST NVD, “CVE-2026-72530,” date not provided in the supplied material.
- Kaspersky Securelist, “Head Mare targets TrueConf Server with PhantomCore,” date not provided in the supplied material; only the reference title was available.
8. Adverse Trace position
Adverse Trace retains the verified assessment of CVSS 9.3 CRITICAL, EPSS 0%, and NOT in CISA KEV, notwithstanding conflicting CISA-ADP metadata in the supplied NVD history. Affected systems reachable over 4307/TCP require P1 exposure reduction because the confirmed vulnerability path permits unauthorised arbitrary-script execution; however, compromise, ransomware use and actor attribution are not established. The technical mechanism is effectively single-sourced, while the Head Mare/PhantomCore association is unconfirmed and single-sourced; verify before enforcement. Adverse Trace will monitor for a vendor-fixed release, reconciliation of the KEV discrepancy, confirmed exploitation reporting and validated detection artefacts.
Published via PulseTrace — Adverse Trace threat intelligence.