<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — TrueConf</title><description>Actively exploited vulnerabilities affecting TrueConf products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/trueconf.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-72529 — TrueConf Server Missing Authentication for Critical Function Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-72529</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-72529</guid><description>TrueConf Server has a critical flaw where attackers need no credentials whatsoever to reach a sensitive function exposed on port 4307/TCP. Anyone with network access to that port can execute arbitrary scripts on the server, effectively gaining the ability to run malicious code remotely without logging in. This is a high-impact, low-barrier attack — no stolen credentials or social engineering required, making it especially dangerous for any TrueConf Server instance reachable from untrusted networks.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate><category>TrueConf</category><category>Server</category></item><item><title>CVE-2026-72530 — TrueConf Server Code Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-72530</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-72530</guid><description>TrueConf Server contains a code injection flaw that lets an unauthenticated remote attacker exploit port 4307/TCP to escape the application&apos;s sandboxed environment and run arbitrary code directly on the underlying host. This means full host-level compromise is possible without any credentials, making internet-exposed TrueConf Server deployments particularly dangerous. The vulnerability effectively eliminates the containment boundary the server relies on for isolation.</description><pubDate>Thu, 20 Aug 2026 00:00:00 GMT</pubDate><category>TrueConf</category><category>Server</category></item><item><title>CVE-2026-3502 — TrueConf Client Download of Code Without Integrity Check Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-3502</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-3502</guid><description>TrueConf Client fails to verify the integrity of update packages it downloads, meaning an attacker who can intercept or redirect the update delivery path — such as through a man-in-the-middle position or DNS manipulation — can swap in a malicious payload. If the updater installs or executes that tampered package, the attacker gains arbitrary code execution with the same privileges as the updating process or the logged-in user. This is a serious supply-chain-style risk affecting any system running TrueConf Client.</description><pubDate>Thu, 02 Apr 2026 00:00:00 GMT</pubDate><category>TrueConf</category><category>Client</category></item></channel></rss>