A security flaw that allows harmful code injection has been found in TrueConf Server, a video conferencing and team communication tool that some website owners host on their web hosting accounts. The vulnerability lets an unauthorized remote attacker with access to the server’s 4307/TCP network port send a specially crafted script to break out of the platform’s isolated security environment, and run any code of their choice on the underlying host server system.
If you use TrueConf Server on your hosting account, this means an outside party with access to that 4307/TCP port could execute custom code directly on the server that runs your website and the TrueConf service.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-72530