CISA orders urgent patching of two actively exploited TrueConf video conferencing server flaws
CISA added two critical TrueConf Server vulnerabilities, CVE-2026-72529 and CVE-2026-72530, to its Known Exploited Vulnerabilities catalog on August 20, giving federal agencies days to patch. Kaspersky says the hacktivist group Head Mare has been exploiting them since July to deploy PhantomCore malware inside Russian companies. Per SecurityWeek and The Hacker News.
CISA added two critical-severity TrueConf Server vulnerabilities, CVE-2026-72529 and CVE-2026-72530, to its Known Exploited Vulnerabilities catalog on Thursday, August 20, 2026, ordering federal agencies to patch the first within three days and the second within two weeks. All TrueConf Server versions since 2022 are affected. Attackers reach the server through port 4307, which is open by default; the first flaw lets them call an undocumented function and run a script inside an isolated environment, and the second lets them break out of that sandbox and run arbitrary commands on the host with NT AUTHORITY SYSTEM privileges. Kaspersky reported it detected Head Mare, a hacktivist group active since 2023 that targets organizations in Russia and Belarus, exploiting the same flaw chain since July 2026 to replace legitimate TrueConf client installers with poisoned versions carrying the PhantomCore backdoor, plus a second backdoor called PhantomGraph that uses Microsoft OneDrive for command-and-control. TrueConf patched the flaws in versions 5.3.9, 5.4.9 and 5.5.5, released June 18, 2026. Sources: SecurityWeek, The Hacker News.