If you run TrueConf Server on your hosted account, a code injection security flaw has been found in the platform. This issue could allow an unauthorized remote attacker who can access port 4307/TCP on your server to send a specially crafted script that breaks out of the platform’s isolated security environment, and run unapproved code directly on your host server.
If this vulnerability is exploited, attackers could access sensitive data stored on your server, modify or disrupt your website and connected services, or use your server’s resources for malicious activity without your knowledge.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72530