TrueConf, Microsoft, and Elementor: What This Week's Vulnerabilities Mean for Your Business
Two vulnerabilities in TrueConf Server landed on CISA’s Known Exploited Vulnerabilities catalogue yesterday. Not flagged as likely to be exploited. Not theoretical. Confirmed active exploitation, in the wild, right now.
That is where this week’s threat brief starts.
Three stories matter today. The TrueConf KEV additions. A significant overnight Microsoft disclosure. And an Elementor Pro flaw that puts six million WordPress sites in range of a complete takeover. Pick the right two or three from this week’s noise, and you have a clear picture of the actual risk surface for a UK small business in August 2026.
TrueConf Server: Two KEV Entries, Actively Exploited
TrueConf is a video conferencing and collaboration platform. It is not ubiquitous in the way Teams or Zoom is, but it has a presence across enterprise and public sector environments, and it turns up in supply chains. If your MSP or a supplier uses it, the exposure is relevant to you even if you have never heard of the product.
CISA added two flaws on 20 August 2026.
CVE-2026-72529 is a missing authentication for critical function vulnerability. Translation: an attacker with network access to port 4307/TCP can execute an arbitrary script on the server without providing any credentials. No username. No password. No prior access. Just network reachability and the flaw.
CVE-2026-72530 is a code injection vulnerability. An attacker can craft a specific script that breaks out of TrueConf’s isolated environment and executes arbitrary code directly on the host operating system. Again, no authentication required.
Combined, these two vulnerabilities describe a path from network access to full host compromise. The CISA KEV listing means this is not a theoretical exercise. Attackers are doing it.
The required action from CISA is clear: apply vendor mitigations immediately, or discontinue use of the product if mitigations are unavailable.
If TrueConf Server is in your environment, the question is not whether to act. The question is how fast you can act.
Microsoft’s Overnight Disclosure: Four CVSS 10.0 Flaws
The Microsoft disclosure published on 20 August 2026 is the kind of thing that gets lost in the volume of vendor security bulletins. It should not be lost.
Four separate vulnerabilities scored CVSS 10.0, the maximum possible severity rating. All four allow remote code execution or privilege escalation without authentication.
CVE-2026-65770: Argument injection in Azure Managed Instance for Apache Cassandra. Unauthenticated remote code execution over a network. If your business uses managed database services in Azure, this is directly relevant.
CVE-2026-65801: Server-side request forgery in Microsoft Exchange Online. An unauthenticated attacker can use this to escalate privileges over a network. Exchange Online is the email infrastructure for a significant proportion of UK small businesses using Microsoft 365.
CVE-2026-65816 and CVE-2026-69555: Two separate flaws in Azure Arc, both scored 10.0, both allowing privilege escalation. Azure Arc is the service that lets organisations manage on-premises and multi-cloud infrastructure from a single Azure control plane. It is increasingly common in hybrid environments.
Additionally, CVE-2026-69836: Deserialisation of untrusted data in Microsoft Entra ID (formerly Azure Active Directory) allows unauthenticated remote code execution. Entra ID is the identity backbone for Microsoft 365. If you use Microsoft 365, you use Entra ID.
The pattern across these disclosures is consistent. These are not obscure components. Exchange Online, Entra ID, Azure Arc: these are the load-bearing walls of the Microsoft cloud estate. Maximum severity flaws in these services affect the organisations that depend on them, including the vast majority of UK SMBs that moved to Microsoft 365 in the last five years.
Microsoft cloud services patch on Microsoft’s timeline, not yours. But the action point here is to verify your tenant configuration, check for any anomalous activity in your Entra ID logs, and ensure your Microsoft 365 environment is being actively monitored.
Elementor Pro: Six Million WordPress Sites at Risk
Elementor Pro is a premium WordPress page builder plugin installed on an estimated six million websites. It is the kind of tool a small business installs once, forgets about, and never thinks of as a security surface.
A critical unauthenticated file upload vulnerability (CVE-2026-32475) allows an attacker to upload PHP files to the web server and execute them. From there, the documented attack paths include installing backdoors and creating malicious administrator accounts.
Patchstack, which reported the vulnerability, stated they expect active exploitation to follow. The disclosure is fresh. The attack surface is enormous.
If your business website runs on WordPress and uses Elementor Pro, the question is simple: what version are you running, and who is responsible for keeping it updated?
This is exactly the kind of vulnerability that catches small businesses. The website was built by an agency two years ago. The agency relationship ended. Nobody is applying plugin updates. The site sits there, attracting search traffic, processing contact form submissions, and now hosting an attacker’s backdoor.
Why This Matters for Your Supply Chain
These three stories illustrate a consistent pattern in 2026’s threat landscape. The attack surface is not just your own systems. It is the software your suppliers run, the platforms your website sits on, and the cloud infrastructure your productivity tools depend on.
TrueConf may not be in your business. But if it is in your MSP’s environment, or in the environment of a key supplier, the compromise of that system creates an access point into your data.
Elementor Pro is almost certainly in your environment if you have a WordPress site and did not build it yourself. Most small business websites are built on WordPress. Most use premium plugins. Almost none have a defined owner responsible for keeping those plugins updated.
Microsoft cloud infrastructure is managed by Microsoft. But anomalous behaviour in your Microsoft 365 tenant is something you can detect, if you have logging enabled and someone looking at it.
How to Turn This Into a Competitive Advantage
Security awareness at this level of specificity is not common in small businesses. Most owners and directors are operating on a six-month lag from current threat intelligence, if they have any exposure to it at all.
Knowing which tools are in your environment, knowing when those tools have been compromised, and being able to demonstrate a documented patching and monitoring process: these are differentiators in procurement conversations, supplier qualification questionnaires, and due diligence processes.
The organisations that lose contracts over security are usually not the ones with catastrophic failures. They are the ones that cannot answer basic questions about their patch status or incident response capability. Being able to answer those questions, with evidence, is a competitive position.
Making the Business Case
If you need to have this conversation with a director or a finance lead, three arguments carry weight.
First, the cost of a breach is not the ransom figure in the news. It is the operational downtime, the customer notification obligation under UK GDPR, the ICO investigation, and the reputational damage to a business that cannot afford a PR crisis. The Elementor Pro scenario: your website hosts an attacker’s backdoor for three months before anyone notices. Every customer who submitted a contact form in that period is a potential data subject. That is a reportable incident.
Second, patching is not optional under Cyber Essentials. The Cyber Essentials scheme, which is the baseline certification that an increasing number of public sector and enterprise buyers require from their suppliers, mandates that software is patched within 14 days of a critical update being released. The TrueConf KEV entries and the Microsoft disclosures both trigger that obligation for any organisation that holds the certification.
Third, the cost of monitoring is lower than the cost of discovery. Finding out you have been compromised because a customer tells you is significantly more expensive than finding out because your monitoring caught it. Basic Microsoft 365 audit logging is included in most business subscriptions. Turning it on costs nothing.
What to Do Before Friday
Check your TrueConf exposure. Ask your IT provider or MSP directly: do we or any of our suppliers run TrueConf Server? If yes, what is the patch status and is port 4307/TCP exposed to the internet? If you cannot get a clear answer, that is itself a finding worth escalating.
Review your WordPress site. Log in to your WordPress admin panel. Go to Plugins. Look for Elementor or Elementor Pro. If you see it, check the version and compare it to the latest release on the Elementor website. If you do not have access to your own website’s admin panel, that is a separate problem to fix immediately.
Enable Microsoft 365 audit logging if it is not already active. In the Microsoft 365 admin centre, under Compliance, verify that audit logging is turned on. It takes approximately two minutes. Without it, you have no visibility into what is happening in your Exchange Online or Entra ID environment.
Check your Entra ID sign-in logs for anomalies. In the Microsoft Entra admin centre, look at the sign-in logs for any successful authentications from unexpected locations or unusual times. Given the Entra ID RCE disclosure, this is worth ten minutes of attention today.
Ask your MSP what their patch SLA is for critical vulnerabilities. The answer should be 14 days or fewer. If they cannot tell you, or if the answer is longer, that is a contractual gap worth addressing in writing.
Before you go: follow the show wherever you listen, leave a rating or review, drop a comment with your thoughts, and share this with someone who would actually find it useful. The people who need to hear this most are usually the ones who are not already looking for it.