Threat Intel
CISA Expands KEV Catalog with Two New TrueConf Server Vulnerabilities
Two new CVEs—CVE‑2026‑72529 and CVE‑2026‑72530—have been added to CISA’s Known Exploited Vulnerabilities catalog. Both target the TrueConf Server platform, one bypassing authentication and the other enabling code injection. Federal agencies must prioritize patching under BOD 26‑04, while all organizations are urged to adopt risk‑based remediation and can submit additional KEVs via CISA’s nomination form.
New KEV Additions
CISA has just added two new CVEs to its Known Exploited Vulnerabilities catalog. Both target the TrueConf Server platform and have been actively abused in the wild.
- CVE-2026-72529 – Missing authentication on a critical function, allowing attackers to take full control of the server.
- CVE-2026-72530 – Code‑injection flaw that can execute arbitrary commands on the host.
Implications for Federal Agencies
Under Binding Operational Directive 26‑04, federal civilian executive branch agencies must prioritize remediation of high‑risk KEVs on publicly exposed assets that grant total control. The new TrueConf flaws fit that bill, so patching should be a top priority.
What You Should Do
All organizations, not just federal agencies, are encouraged to adopt risk‑based vulnerability management and prioritize remediation of KEV catalog entries. If you discover an exploited vulnerability not yet listed, submit it via CISA’s KEV Nomination Form.