Announcements

TrueConf Server: TrueConf Server Missing Authentication for Critical Function Vulnerability

  • 22nd August 2026
A security vulnerability has been identified in TrueConf Server. The flaw stems from a missing authentication check for a critical server function, meaning unauthorized users do not need valid login credentials to access this sensitive feature.If your TrueConf Server instance is reachable via port 4307/TCP over a network, a remote attacker could ...
Continue reading

TrueConf Server: TrueConf Server Code Injection Vulnerability

  • 22nd August 2026
A security flaw that allows harmful code injection has been found in TrueConf Server, a video conferencing and team communication tool that some website owners host on their web hosting accounts. The vulnerability lets an unauthorized remote attacker with access to the server’s 4307/TCP network port send a specially crafted script to break out ...
Continue reading

Synacor Zimbra Collaboration Suite (ZCS): Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability

  • 22nd August 2026
A security vulnerability has been identified in Zimbra Collaboration Suite (ZCS), the email, calendar, and team collaboration platform used by some of our clients for business communications. This flaw is classified as an operating system command injection vulnerability, a type of security hole that can let unauthorized parties run commands ...
Continue reading