CISA urges immediate patching of exploited TrueConf vulnerabilities

CISA urges immediate patching of exploited TrueConf vulnerabilities

The US cybersecurity agency CISA warned federal authorities on Thursday that threat actors have exploited two vulnerabilities in TrueConf.

TrueConf is a secure on-premise video conferencing platform and is based on Scalable Video Coding (SVC) to connect client applications over a dedicated enterprise server.

All TrueConf Server releases since 2022 contain two critical severity bugs, tracked as CVE-2026-72529 and CVE-2026-72530, which allow attackers to execute arbitrary code.

The two vulnerabilities can be exploited by remote attackers who have access to the TrueConf server via port 4307/TCP. CVE-2026-72529 allows the attacker to call an undocumented function and execute arbitrary scripts, while CVE-2026-72530 allows the attacker to escape the isolated environment and execute scripts on the host system.

The exploited vulnerabilities were addressed in June 2026, in TrueConf Server versions 5.3.9, 5.4.9 and 5.5.5.

On Thursday, CISA added Both will be included in the Known Exploited Vulnerabilities (KEV) catalog and federal authorities will be required to address the former within three days and the latter within two weeks.

Advertising. Scroll to continue reading.

While CISA did not provide details on the observed exploitation measures earlier this month, Kaspersky reported warned that they were exploited by the hacktivist group Head Mare to deploy the PhantomCore malware.

Head Mare has been active since at least 2023, targeting organizations in Russia and Belarus with destructive attacks. It has been observed using file-encrypting malware and demanding ransom payments from its victims, but the group does not appear to be financially motivated.

As part of the attacks Kaspersky investigated, hackers exploited CVE-2026-72529 and CVE-2026-72530 to compromise an organization’s TrueConf server and replace one of its files with a web shell.

“This web shell is later used to collect information about the attacked organization’s IT infrastructure, gain privileged access to the TrueConf server database and replace the legitimate client installers,” Kaspersky says.

The threat actors placed malicious TrueConf client installers on the server. Once executed on the employee’s systems, they installed PhantomCore, a malware typically associated with the Head Mare intrusions.

In addition, the attackers installed a backdoor on the *nix servers running TrueConf and another on *nix systems. The former uses the TrueConf protocol for command and control (C&C) communication, while the latter uses GitHub.

TrueConf server owners are recommended to update to a patched version, scan their environments for Indicators of Compromise (IoCs), check for malicious artifacts, and switch credentials for all potentially affected accounts if an intrusion is detected.

Related: Hackers are targeting Zimbra servers as part of an active exploitation campaign

Related: Atlassian and Splunk patch dozens of critical, high-severity vulnerabilities

Related: MLflow vulnerability exploited for cloud credential theft

Related: Cisco addresses critical crosswork and secure workload vulnerabilities

Leave a Reply

Your email address will not be published. Required fields are marked *