CISA directs the feds to patch actively exploited TrueConf Server vulnerabilities

CISA

The US Cybersecurity and Infrastructure Security Agency (CISA) has ordered US federal agencies to prioritize the patching of two actively exploited vulnerabilities in the TrueConf Server standalone communications platform.

TrueConf Server is designed for secure corporate messaging and video conferencing and, unlike cloud-based software like Zoom or Microsoft Teams, it runs on an organization’s local area network (LAN).

The most serious is a critical missing authentication security flaw (tracked as CVE-2026-72529), which allows unprivileged attackers to remotely execute arbitrary scripts on raw servers.

image

“A remote, unauthorized attacker connecting to TrueConf Server over 4307/TCP could call an undocumented critical function and execute arbitrary script on the server,” the TrueConf security team explains.

The second is another critical vulnerability (CVE-2026-72530), which unauthenticated threat actors can use via highly sophisticated code injection attacks to obtain remote code execution.

“Mismanagement of code generation could allow an attacker who has achieved code execution in the isolated environment of TrueConf Server to escape the sandbox and execute arbitrary commands on the underlying operating system,” TrueConf adds.

On Thursday, CISA add the two disadvantages to his own KEV catalog and ordered US Federal Civilian Executive Branch (FCEB) agencies to secure their servers within two weeks, by September 3.

“This type of vulnerability is a common attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” the cybersecurity agency warned.

Although CISA did not share details about these attacks, cybersecurity company Kaspersky said hacktivist group Head Mare has been exploiting CVE-2026-72529 and CVE-2026-72530 since at least July 2026 to replace client installers with malicious versions designed to deploy backdoor malware.

According to Kaspersky, multiple Head Mare campaigns targeted Russian organizations in various industry sectors, including transportation, energy, IT, electronics and software development.

In April 2026, Check Point Research also reported that hackers had targeted another TrueConf flaw (CVE-2026-3502) in zero-day attacks called “Operation True Chaos” and linked to Chinese threats, compromising users through trojanized client updates.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *