Skip to content
October 1, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • STUN vs. TURN Servers in WebRTC
  • Technique

STUN vs. TURN Servers in WebRTC

Do Son October 30, 2022 5 minutes read
WebRTC bug

Video calling technology has taken over the world, and people can see and hear each other via the Internet in a matter of seconds if they want to. Previously, users had to download programs and install them on their devices to use video conferencing services. Not to mention the era when the software was stored and shared on disks. But now, there are dedicated video conferencing platforms that allow peer-to-peer communication almost instantly. This is possible thanks to WebRTC technology. For users, it might look like the connection just happens, but many special servers are working for two people to speak to each other online in real-time. Digital Samba (https://www.digitalsamba.com/video-api) is one of the platforms that allow such simple communication.

Servers Needed for P2P Communication

WebRTC, to put it simply, is a connection established between two different browsers. It is the most simple connection as it only features two people. However, with video conferencing platforms, thousands of people can communicate within one digital call simultaneously. But the smallest connection between two Internet users is a good example. To bring these two people together, it is necessary to establish a connection with the server. A server does the coordination necessary for the video connection to work. At this stage, two types of servers can be used: STUN or TURN.

About STUN Servers

To communicate online in real time and use video, audio, and file sharing in the process, it is necessary to connect to a specific server. Both Session Traversal Utilities for NAT or STUN and Traversal Using Relays around NAT or TURN servers are incorporated in the process of digital peer-to-peer communication. However, they are utilized on different occasions.

Before the connection between the two video conferencing platform users can be established, a server needs to identify the IPs of both users. The software using WebRTC usually works with STUN servers. They are fast, easy to use, and do not generate much traffic.

When the connection between two users happens, they can easily exchange data directly with each other. However, in some cases, firewalls prohibit the software from connecting to the STUN servers. That is why TURN servers are used as an alternative.

About TURN Servers

Because of a firewall or other limitations, access to a certain server can be limited. Because there are no identifiers that would help two devices to discover each other and connect, another solution is necessary. It is when TURN servers come into play. However, when a TURN server helps to finally connect the two dots, it remains in the way of data exchange, unlike a STUN server. This usually results in slower operation, which is a price you have to pay for establishing a connection when the other option does not work out. This also often means increased expenses.

Although TURN servers are slower and more expensive, they can save your connection if STUN servers cannot be used. In any case, a connection between two or more people is established, and it becomes possible to communicate via a video call live.

Benefits of Video Conferencing

Being able to communicate over the Internet in real-time and not only hear but also see the people you are talking to is a great invention. In addition, modern video conferencing software opens up new opportunities for collaboration, which allows for convenient and efficient work and studying. Software like Digital Samba is extremely useful and safe thanks to its encryption methods called E2EE. It is GDPR-compliant as well, which contributes to its security. Here are some of the reasons why you should consider video conferencing services:

  • Easier communication – previously, remote work and even working in the office were not very convenient in many cases. Communicating via the phone made it impossible to see the other person, and sharing files or ideas was more difficult. With video conferencing, you can connect with your colleagues easily from any point on the planet.
  • Cutting costs – hosting a conference for many employees of a company often requires traveling to a certain destination. If your company has offices in different cities or even countries, it is rather difficult and costly to bring people together. Video calls are incredibly affordable and handy when it comes to arranging a meeting for people from all across the world.
  • Increased efficiency – convenient conditions and tools for collaboration result in enhanced efficiency. When your employees can jump on a video call within seconds to discuss certain questions and ask for advice, their workflow becomes much more smooth and brings better results.
  • Affordable – even if you want to have a dedicated video conference room with all the necessary equipment, it is cost-efficient as high-quality hardware and software will serve for many years. However, you do not even need extremely expensive equipment for video conferencing. A simple laptop or even a smartphone will work just fine.
  • Recording videos – whether you need to record your meeting for the archive or you want to create a series of live workshops and upload them on your site afterward, this is possible with video calling software. Simply start recording at the beginning of your live stream session and store the full video in a cloud afterward. Cloud storage is especially convenient for such large videos as you will not need to store all the files within the company.
  • Host video conferences of any scale – from a face-to-face video chat with a colleague to a live stream for your clients with thousands of attendees, video conferencing solutions are very scalable and can suit any of your corporate needs. Host a variety of events or meetings using a single software.

Video conferencing technology has come a long way, and modern servers allow connecting with other users easily within seconds.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-75957CVSS 9.8
    The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass...
    📅 Updated: Oct 1, 2026
  • CVE-2026-15989CVSS 9.8
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in...
    📅 Updated: Oct 1, 2026
  • CVE-2026-92966CVSS 9.1
    The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable...
    📅 Updated: Oct 1, 2026
  • CVE-2026-101148CVSS 10.0
    The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an...
    📅 Updated: Oct 1, 2026
  • CVE-2026-62329CVSS 9.8
    Vulnerability Type: CWE-1392: Use of Default Credentials Attack type: Unauthenticated remote Impact: Unauthenticated users can access the default...
    📅 Updated: Oct 1, 2026
  • CVE-2026-103264CVSS 9.3
    Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware...
    📅 Updated: Oct 1, 2026
  • CVE-2026-103244CVSS 9.3
    ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to...
    📅 Updated: Oct 1, 2026
  • CVE-2026-57496CVSS 9.6
    ## REST Path Traversal Bypasses Token Redaction in netlicensing-mcp ### Summary The `netlicensing_get_product` MCP tool in `netlicensing-mcp` interpolates...
    📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.