CISA adds TrueConf and Zimbra and Oracle WebLogic to KEV

CISA adds TrueConf and Zimbra and Oracle WebLogic to KEV


CISA has added multiple vulnerabilities affecting TrueConf Server, Zimbra Collaboration Suite and Oracle HTTP Server/WebLogic Server Proxy Plug-in to its Known Exploited Vulnerabilities (KEV) catalog. These entries are important because KEV inclusion indicates that exploitation has been observed and organizations should prioritize remediation.

TrueConf Server — CVE-2026-72529

CVE-2026-72529 is a missing-authentication vulnerability in TrueConf Server. A remote, unauthenticated attacker who can reach TCP port 4307 can invoke an undocumented function and execute an arbitrary script.

The affected branches include TrueConf Server 5.3.x, 5.4.x and 5.5.x up to the fixed releases. The vulnerability effectively provides a remote entry point without requiring valid credentials.

TrueConf Server — CVE-2026-72530

CVE-2026-72530 is a code-injection vulnerability in the same TrueConf Server component. An attacker with network access to TCP/4307 can submit a specially crafted script that escapes the application’s isolated environment and executes arbitrary code on the underlying host.

The combination of these two flaws is particularly serious: one provides an unauthenticated execution path, while the second can enable host-level code execution.

Zimbra Collaboration Suite — CVE-2026-73570

CVE-2026-73570 is an unauthenticated remote-code-execution vulnerability in Zimbra Collaboration Suite.

The issue affects ZCS versions before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Improper sanitization of untrusted input during SNMP notification processing allows an attacker to send specially crafted SMTP requests that can result in arbitrary operating-system command execution as the Zimbra user.

This makes configuration assessment important. Organizations should not simply check the Zimbra version; they should also determine whether the vulnerable zimbra-snmp component and SNMP notification functionality are enabled.

Oracle WebLogic / Oracle HTTP Server — CVE-2026-21962

CVE-2026-21962 affects the WebLogic Server Proxy Plug-in used with Oracle HTTP Server and Microsoft IIS.

The vulnerability can be exploited by an unauthenticated attacker over HTTP and affects Oracle HTTP Server versions 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0.

Oracle addressed the vulnerability in its January 2026 Critical Patch Update.

What Security Teams Should Do

These are not vulnerabilities to leave in the normal patch backlog.

  • Identify exposed TrueConf, Zimbra and Oracle WebLogic/HTTP Server instances.
  • Verify both software versions and vulnerable configurations.
  • Patch to the vendor-provided fixed releases.
  • Restrict unnecessary external access while remediation is underway.
  • Review logs and server artifacts for previously exploited systems.
  • Treat already-exposed vulnerable systems as potential compromise candidates, particularly where unauthenticated remote execution was possible.

Bottom Line

The common thread across these vulnerabilities is remote exploitation with little or no authentication friction. TrueConf provides an attack path through TCP/4307, Zimbra can reach OS command execution under the vulnerable configuration, and the Oracle flaw exposes the WebLogic proxy layer to unauthenticated HTTP exploitation.

KEV status changes the priority: identify, patch, validate, and investigate — rather than simply tracking the CVEs.

Comments

No comments yet. Why don’t you start the discussion?

    Leave a Reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.