← Incidents
INCIDENT 180Exploited vulnerabilityLOW / UNDER REVIEWSourced
CVE-2026-72530 added to CISA KEV: TrueConf Server Code Injection Vulnerability
<p>CISA has added two new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation. </p> <ul> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-72529" target="_blank">CVE-2026-72529</a> TrueConf Server Missing Authentication for Critical Function Vulnerability </li> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-72530" target="_blank">CVE-2026-72530</a> TrueConf Server Code Injection Vulnerability</li> </ul> <p>These types of vulnerabilities…
Last evidence update
20 AUG 2026 · 12:00 UTC
Source count
3
Status
reported
ManufacturingGovernmentCVE-2026-72530CVE-2026-72529
Preceded by
Weak signals the observatory recorded before this incident became visible.
Observation history
How this record has evolved as evidence accumulated.
21 AUG · 05:03 UTC
Initial report
21 AUG · 05:03 UTC
Second independent source
21 AUG · 05:03 UTC
Related CVE identified (CVE-2026-72529)
21 AUG · 05:03 UTC
Second independent source
21 AUG · 05:03 UTC
Summary updated from new evidence
Evidence