CVE-2026-72530: TrueConf Server
TrueConf Server包含一個程式碼注入脆弱性,可以允許未經授權的遠端攻擊者透過埠4307/TCP訪問網路,使用專門設計的指令碼來突破孤立的環境,並在主機系統中執行任意程式碼。
CISA (English)
TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.
- 廠商
- TrueConf
- 產品
- Server
- 漏洞
- TrueConf Server Code Injection Vulnerability
- 加入日期
- 2026年8月20日
- CISA 修補期限(美國聯邦機關)
- 2026年9月3日
- 已知用於勒索軟體攻擊
- 未知
- 弱點(CWE)
- CWE-94
參考資料
本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。
最後更新: · 目錄版本 2026.10.02