Exploited Known exploited (KEV) CVE-2026-72529

Two entries added the same day drew due dates three days and 14 days out — missing authentication and code injection in TrueConf Server

TrueConf Server Added to KEV Aug 20, 2026 Federal remediation due 2026-08-23

TrueConf Server contains a missing authentication for critical function vulnerability, allowing a remote unauthorized attacker reaching port 4307/TCP to execute an arbitrary script. It was added to the CISA Known Exploited Vulnerabilities catalog on 2026-08-20 with a due date three days later, while another entry for the same product added the same day carries a 14-day due date.

Key facts

  • CVE IDCVE-2026-72529
  • Affected (vendor / product)TrueConf Server
  • CWECWE-306
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-08-23 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • TrueConf Server contains a missing authentication for critical function vulnerability (CWE-306); an unauthorized attacker reaching port 4307/TCP could execute an arbitrary script.
  • Added to KEV on 2026-08-20 with a due date of 2026-08-23, a three-day grace period.
  • CVE-2026-72530 for the same product (code injection, CWE-94) was added the same day with a due date of 2026-09-03, a 14-day grace period.
  • CVE-2026-72530 could allow a crafted script to break out of the isolated environment and execute arbitrary code on the host.
  • Across the 1,687 records this site holds as of 2026-09-02, grace periods have a median of 21 days, a minimum of 1 and a maximum of 184.

1Same day, same product, different deadlines

Every entry in the CISA Known Exploited Vulnerabilities catalog carries its own due date, and two entries for the same product added on the same day show clearly that these are not uniform. TrueConf Server CVE-2026-72529 and CVE-2026-72530 were both added on 2026-08-20. The first is due three days later; the second, 14.

2The two side by side

CVE-2026-72529 (three-day grace)CVE-2026-72530 (14-day grace)
Missing authentication for critical function (CWE-306)Code injection (CWE-94)
A remote unauthorized attacker could execute an arbitrary scriptA crafted script could break out of the isolated environment and execute arbitrary code on the host
Reached over the network via port 4307/TCPReached over the network via the same port 4307/TCP
Due 2026-08-23Due 2026-09-03

The port used for access is the same, and both are described as usable remotely without authorization. That the grace periods still differ suggests due dates are not decided by a simple ranking of severity. Spread of exploitation, availability of mitigations and difficulty of remediation are among the conditions such a value plausibly reflects.

3Placing them in the distribution

Across the 1,687 KEV records this site holds as of 2026-09-02, the grace period from date added to due date has a median of 21 days, a minimum of 1 and a maximum of 184. Both of these entries fall below the median, and three days is a sharply compressed instruction. Fourteen days, by contrast, sits near a monthly maintenance cycle and can be handled within ordinary operations. Two entries arriving the same day still call for different movements.

4Adjacent numbers, separate handling

Vulnerabilities with nearly consecutive CVE numbers often emerge together from one investigation or one report. In the catalog, though, they are separate entries managed against separate deadlines. From an operations standpoint that means checking due dates entry by entry rather than batching by number proximity.

The required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use. Verify applicability with official vendor information and your own environment.

Why it matters

Since due dates diverge even for the same product over the same access path, a vulnerability register needs deadlines at the entry level rather than the product level. Batching by number proximity drops the entries with the shortest deadlines.

FAQ

Why do same-day additions get different deadlines?
The record gives no reason. Due dates plausibly reflect spread of exploitation, availability of mitigations and difficulty of remediation rather than a simple severity ranking.
Can vulnerabilities with adjacent numbers be handled together?
The catalog manages them as separate entries against separate deadlines, so due dates should be checked entry by entry rather than batched by number proximity.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#TrueConf#Missing authentication#Due dates
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.