Two entries added the same day drew due dates three days and 14 days out — missing authentication and code injection in TrueConf Server
TrueConf Server contains a missing authentication for critical function vulnerability, allowing a remote unauthorized attacker reaching port 4307/TCP to execute an arbitrary script. It was added to the CISA Known Exploited Vulnerabilities catalog on 2026-08-20 with a due date three days later, while another entry for the same product added the same day carries a 14-day due date.
Key facts
- CVE IDCVE-2026-72529
- Affected (vendor / product)TrueConf Server
- CWECWE-306
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-08-23 (U.S. federal civilian agencies, BOD 22-01)
Key points
- TrueConf Server contains a missing authentication for critical function vulnerability (CWE-306); an unauthorized attacker reaching port 4307/TCP could execute an arbitrary script.
- Added to KEV on 2026-08-20 with a due date of 2026-08-23, a three-day grace period.
- CVE-2026-72530 for the same product (code injection, CWE-94) was added the same day with a due date of 2026-09-03, a 14-day grace period.
- CVE-2026-72530 could allow a crafted script to break out of the isolated environment and execute arbitrary code on the host.
- Across the 1,687 records this site holds as of 2026-09-02, grace periods have a median of 21 days, a minimum of 1 and a maximum of 184.
1Same day, same product, different deadlines
Every entry in the CISA Known Exploited Vulnerabilities catalog carries its own due date, and two entries for the same product added on the same day show clearly that these are not uniform. TrueConf Server CVE-2026-72529 and CVE-2026-72530 were both added on 2026-08-20. The first is due three days later; the second, 14.
2The two side by side
The port used for access is the same, and both are described as usable remotely without authorization. That the grace periods still differ suggests due dates are not decided by a simple ranking of severity. Spread of exploitation, availability of mitigations and difficulty of remediation are among the conditions such a value plausibly reflects.
3Placing them in the distribution
Across the 1,687 KEV records this site holds as of 2026-09-02, the grace period from date added to due date has a median of 21 days, a minimum of 1 and a maximum of 184. Both of these entries fall below the median, and three days is a sharply compressed instruction. Fourteen days, by contrast, sits near a monthly maintenance cycle and can be handled within ordinary operations. Two entries arriving the same day still call for different movements.
4Adjacent numbers, separate handling
Vulnerabilities with nearly consecutive CVE numbers often emerge together from one investigation or one report. In the catalog, though, they are separate entries managed against separate deadlines. From an operations standpoint that means checking due dates entry by entry rather than batching by number proximity.
The required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use. Verify applicability with official vendor information and your own environment.
Why it matters
Since due dates diverge even for the same product over the same access path, a vulnerability register needs deadlines at the entry level rather than the product level. Batching by number proximity drops the entries with the shortest deadlines.
FAQ
Why do same-day additions get different deadlines?
Can vulnerabilities with adjacent numbers be handled together?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).