cisaregulatorNewsThe Broadside1 min read

CISA Adds Two TrueConf Server Vulnerabilities to KEV Catalog

Both carry 2026 CVE IDs and already show active exploitation, triggering BOD 26-04 remediation deadlines for federal agencies.


TL;DR

CISA added CVE-2026-72529 and CVE-2026-72530, a missing-authentication flaw and a code injection vulnerability in TrueConf Server, to its Known Exploited Vulnerabilities catalog on August 20. Both carry 2026 CVE identifiers, meaning they were disclosed this year and are already under active exploitation. Federal Civilian Executive Branch agencies must prioritize remediation under BOD 26-04, which requires rapid patching of KEV-listed CVEs on publicly exposed assets. Two vulnerabilities in the same product landing in KEV simultaneously isn't the routine single-entry update; it's worth a closer look for any agency running on-premises conferencing infrastructure.

TrueConf Server is a self-hosted video conferencing platform, the kind of on-premises collaboration infra that federal agencies and defense contractors run when cloud conferencing isn't an option. Two vulnerabilities hitting KEV the same day, both in the same product, is a pattern worth noting.

CVE-2026-72529 is a missing authentication for critical function. CVE-2026-72530 is code injection. Together they're the kind of pairing that turns an exposed server into a beachhead: one gets you in, the other lets you run code.

BOD 26-04 requires FCEB agencies to remediate KEV-listed CVEs on internet-facing assets that grant total control post-exploitation. Both of these fit that description. The directive also requires agencies to check for signs of compromise before patching, not just patch and move on. CISA encourages all organizations, not just FCEB, to adopt the same risk-based prioritization, but the binding deadline applies to federal civilian agencies.

For the practitioner: if your agency or organization runs TrueConf Server on a publicly reachable interface, this isn't a routine patch cycle item. Check for compromise, then patch. The fact that two 2026 CVEs in the same product made KEV simultaneously suggests active targeting, not just opportunistic scanning.


Published ·Updated ·Deep Fathom