CISA has added two exploited flaws in TrueConf Server, the Russian-made video conferencing platform, to its Known Exploited Vulnerabilities catalog. The bugs, CVE-2026-72529 and CVE-2026-72530, have both been used in real-world attacks, and US federal agencies have until September 10 to patch.
Kaspersky linked the exploitation to Head Mare, a pro-Ukrainian hacktivist group that has repeatedly targeted Russian organizations across transport, energy, electronics, IT, and software development. An unauthenticated attacker with network access to TCP port 4307, open by default, can run a malicious script through the first flaw. The second lets the attacker break out of the isolated script environment and execute arbitrary code on the server.
Head Mare used that access to plant web shells, move through victims’ infrastructure, gain privileged access to the TrueConf database, and replace the legitimate Windows client installer with a trojanized version carrying the PhantomCore backdoor. That creates risk beyond organizations running vulnerable servers: anyone joining a conference hosted by a compromised third party could download the poisoned client.
The flaws affect TrueConf Server releases going back to 2022. Fixes shipped June 18 in versions 5.3.9, 5.4.9, and 5.5.5. CISA’s KEV addition means federal agencies must act quickly, and other TrueConf admins should treat their conferencing servers as a potential malware distribution point.
