Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it
What happened
CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog after researchers and exploit reports showed real‑world use. The exploit path requires network access to TrueConf’s default service port, making exposed on‑prem servers operationally at risk and a remediation priority. Watch whether vendors publish clear verification artifacts and whether reports show exploitation beyond the initial campaigns
Why the category manager should care
Treat the KEV listing as an operational trigger: inventory, prioritize patches, and lock in contractual remediation terms with suppliers
Key facts
- CISA added CVE-2026-72529 and CVE-2026-72530 to KEV
- Exploitation requires network access to the conferencing service port (researcher notes TCP 4
- Vendor patches published; federal patching window and guidance in effect