CISA orders urgent patch for exploited TrueConf flaws

CISA told federal agencies to patch two TrueConf Server RCE bugs-CVE-2026-72529 and CVE-2026-72530-after observed exploitation; fixes are in Server 5.3.9, 5.4.9 and 5.5.5.

The Cybersecurity and Infrastructure Security Agency directed federal agencies to apply emergency fixes for two critical vulnerabilities in TrueConf Server that allow remote code execution. CISA added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities catalog and set a three-day remediation window for CVE-2026-72529 and a two-week window for CVE-2026-72530.

Both vulnerabilities affect TrueConf Server releases dating back to 2022 and can be reached by attackers with network access to the server on TCP port 4307. CVE-2026-72529 permits an attacker to invoke an undocumented function and run arbitrary scripts inside the application. CVE-2026-72530 allows an attacker to escape the server’s isolated environment and execute code on the host operating system.

TrueConf published patches in June 2026 in Server versions 5.3.9, 5.4.9 and 5.5.5. After the vendor updates, CISA added the two CVEs to its KEV list to accelerate federal remediation under the agency’s required timelines.

Security researchers reported active exploitation of the flaws by a hacktivist group known as Head Mare. The attackers placed a web shell on compromised TrueConf servers to collect infrastructure details, gain privileged access to the server database and replace legitimate client installers with tampered versions. “This web shell is later used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database, and replace the legitimate client installers,” the researchers wrote. When employees installed the modified clients, their endpoints were infected with PhantomCore malware linked to the group’s operations.

Investigators found backdoors installed on Unix-like systems that hosted TrueConf and on other Unix-like hosts. One backdoor used the TrueConf protocol for command-and-control traffic, while another used GitHub as a control channel. The incidents examined included file-encrypting malware and cases where ransom demands were issued.

TrueConf Server operators are advised to update immediately to the patched releases and to block or monitor TCP port 4307 where appropriate. Administrators should scan environments for indicators of compromise, search for web shells and altered installers, check for unusual database activity, and rotate credentials for any accounts that may have been exposed. Servers that cannot be updated immediately should be isolated from external networks and handled according to incident response procedures.

CISA’s KEV catalog is used to prioritize remediation of vulnerabilities with verified exploitation in the wild; inclusion of these two TrueConf CVEs reflects observed malicious activity tied to compromised servers.

Articles by this author