A security flaw has been identified in TrueConf Server, a service some web hosting clients use on their servers. This is a code injection vulnerability, a type of issue that lets unauthorized users run unapproved code through the affected service. To exploit this flaw, an attacker would need network access to port 4307/TCP on your server. If they can reach that port, they can send a specially crafted script to trigger the vulnerability. This script lets them break out of the isolated, restricted environment that TrueConf Server is designed to run in, and execute any commands they want directly on your host server. If an attacker gains the ability to run arbitrary commands on your server, they may be able to access or steal your website and customer data, modify your site’s content, disrupt your site’s availability, or use your server to host malicious content.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72530