CISA Adds Two Remotely Exploitable TrueConf Server Vulnerabilities to KEV Catalog
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two remotely exploitable vulnerabilities in TrueConf Server to its Known Exploited Vulnerabilities (KEV) catalog, warning that both flaws are already being exploited in the wild.
TrueConf Server is a video conferencing and communication platform developed by TrueConf. On August 20, 2026, CISA included CVE-2026-72529 and CVE-2026-72530 in the KEV list after confirming active exploitation.
CVE-2026-72529 stems from missing authentication in a critical function, allowing unauthenticated remote attackers to execute arbitrary scripts. CVE-2026-72530 is a code injection vulnerability that permits attackers to break out of the isolated environment and execute arbitrary code on the host system.
Both vulnerabilities can be exploited remotely over TCP port 4307 without any authentication. Kaspersky rated the issues with CVSS v3.1 base scores of 9.8 and 9.0, classifying both as Critical.
Federal agencies are required to remediate CVE-2026-72529 by August 23, 2026, and CVE-2026-72530 by September 3, 2026. All organizations using the product are advised to apply available patches or mitigations immediately due to the confirmed in-the-wild exploitation.
Related articles
Critical Vulnerability CVE-2026-12342 Allows Remote Code Execution in SailPoint IdentityIQ
SailPoint has disclosed a critical vulnerability in its identity management product IdentityIQ that stems from insufficient input validation in the web service API. The flaw, identified as CVE-2026-12342, permits an attacker on an adjacent network to execute arbitrary code on the IdentityIQ server without requiring authentication. The vulnerability received a CVSSv3.1 base score of 9.6 and is rated Critical. SailPoint published a security advisory on September 28, 2026, and has released patches for all supported affected versions. The company also plans to include the fix in future patch levels. The issue affects the processing of content sent to the web service API, where improper validation allows malicious input to trigger code execution.
WatchGuard Patches Critical API Flaws in Access Points Allowing Unauthenticated Command Execution
WatchGuard has released firmware version 3.4.8 to address three vulnerabilities affecting its access points, two of which are rated critical. The most severe issues, CVE-2026-86102 and CVE-2026-101891, both scored 9.3 on the CVSS scale and reside in the internal API management service. These flaws permit unauthenticated attackers with network access to execute arbitrary shell commands or bypass access controls without requiring any credentials or valid sessions. A third vulnerability, CVE-2026-87969 with a CVSS score of 8.6, involves command injection through the command-line diagnostic interface but requires authenticated administrator privileges. All firmware versions from 1.0 through 3.4.7 are impacted. The vulnerabilities were disclosed on September 28 with no evidence of active exploitation or public proof-of-concept code available at the time. A compromised access point could serve as an internal foothold for further network attacks due to its visibility into corporate traffic.
Spectre Variant Returns: Branch Target Reuse Attack Extracts Root Password Hash from Linux Memory
Researchers from VUSec and Scuola Superiore Sant’Anna have disclosed Branch Target Reuse, a new Spectre v2 variant that exploits stale branch predictor entries in modern CPUs. The attack targets JIT compilers that generate and reuse executable code at runtime, allowing speculative execution of instructions from previously freed memory regions. On Intel systems with existing mitigations enabled, the researchers demonstrated extraction of the root password hash from the Linux kernel in minutes. Practical proof-of-concept exploits were developed against the Linux kernel, while PoCs were also prepared for Firefox and tested on GraalVM. The issue affects Intel, AMD, and Arm processors, although exploitation success depends on the specific JIT environment and predictor state. Defenses have already been merged into the Linux kernel and GraalVM, while Mozilla continues work on site isolation. The findings highlight that Spectre-class issues remain relevant as long as processors rely on aggressive speculative execution.
EASM Uncovers Forgotten Perimeter Assets Including 11-Year-Old Servers Invisible to Standard Scanners
EASM solutions continuously discover external attack surfaces by starting from public data such as company names, domains, WHOIS records, Certificate Transparency logs, and internet-wide scanners like Shodan and Censys. Unlike traditional vulnerability scanners that only check assets from a predefined list, EASM maps unknown shadow IT including forgotten test servers, abandoned marketing subdomains, exposed APIs, and cloud buckets left open to the internet. The technology follows the same reconnaissance path used by attackers and has become essential for mature vulnerability management programs after years of being considered exotic. Major vendors including Palo Alto Networks Cortex Xpanse, CyCognito, Qualys, Rapid7, and Tenable now lead the market, while Russian providers such as Positive Technologies PT EASM, BI.ZONE EASM, and CyberOK PenOps have grown rapidly since 2022. Without an established process for prioritization and remediation, EASM implementations risk generating overwhelming alert volumes rather than reducing risk. The approach is now viewed as a core component of Continuous Threat Exposure Management (CTEM) frameworks.