Brand
TrueConf: actively exploited vulnerabilities
3 vulnerabilities in TrueConf products (Server, Client) are in CISA’s catalog of exploited vulnerabilities, 2 of them added in the last 90 days. Last added: August 20, 2026.
-
3 vulnerabilities added in the last 12 months
-
3 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one TrueConf category to your radar, or open its page.
- Collaboration, telephony and video conferencing 3 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- Server 2 vulnerabilities · Collaboration and video
- Client 1 vulnerability · Collaboration and video
Name used by CISA: TrueConf. Product families: indicative classification by this site.
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this TrueConf list.
Rank 1TrueConf Server
CVE-2026-72529Hunt for compromise (CISA)
TrueConf Server Missing Authentication for Critical Function Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 20, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 2TrueConf Server
CVE-2026-72530TrueConf Server Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Aug 20, 2026
- CISA deadline
- 14 days
- CVSS severity
- 9.0 (critical)
Rank 3TrueConf Client
CVE-2026-3502TrueConf Client Download of Code Without Integrity Check Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 2, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.8 (high)
Follow and verify
Indicative classification, based on the vendor and product names given by CISA. How products are classified.