LIVE · cybersecurity feed
Live wire
vulnerabilityhigh

CISA orders feds to patch actively exploited TrueConf Server flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]

zeroday.news ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to immediately patch two critical vulnerabilities in the TrueConf Server self-hosted communications platform, which are reportedly being actively exploited in the wild. The directive, issued on Thursday, August 21, 2026, requires all U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems by September 3, 2026.

TrueConf Server is a platform designed for secure corporate messaging and video conferencing, operating within an organization's local network rather than as a cloud-based service. CISA emphasized that vulnerabilities of this nature are frequently targeted by malicious actors and present substantial risks to federal systems.

The first vulnerability, tracked as CVE-2026-72529, is a critical missing authentication flaw. It allows an unauthenticated remote attacker to execute arbitrary scripts on unpatched servers by connecting to TrueConf Server over TCP port 4307 and invoking an undocumented critical function. TrueConf's security team confirmed this issue, stating that it enables attackers without privileges to perform remote script execution.

The second vulnerability, CVE-2026-72530, is also rated as critical and involves improper management of code generation. This flaw can be exploited by unauthenticated threat actors through high-complexity code injection attacks. According to TrueConf, an attacker who has achieved code execution within the TrueConf Server's isolated environment can escape this sandbox and execute arbitrary commands on the underlying operating system.

While CISA did not disclose specific details regarding the ongoing exploitation, cybersecurity firm Kaspersky has claimed that a hacktivist group named "Head Mare" has been leveraging both CVE-2026-72529 and CVE-2026-72530 since at least July 2026. The group allegedly uses these vulnerabilities to replace legitimate client installers with malicious versions designed to deploy backdoor malware. Kaspersky reported that multiple Head Mare campaigns have targeted Russian organizations across various sectors, including transportation, energy, IT, electronics, and software development.

These recent advisories follow an earlier report in April 2026 by Check Point Research, which detailed "Operation True Chaos." This campaign involved Chinese threat actors exploiting another TrueConf flaw, CVE-2026-3502, in zero-day attacks to compromise users through trojanized client updates.

vulnerabilitypatchcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Six Maximum-Severity Flaws Found in Cisco Products

Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe. […]

vulnerabilitycritical

Critical Isolated-vm Vulnerability Leads to RCE on Host

The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process. The post Critical Isolated-vm Vulnerability Leads to RCE on Host appeared first on SecurityWeek.

vulnerability

Microsoft warns of max severity Entra ID flaw exploited in attacks

Microsoft has patched a maximum-severity vulnerability in the Entra ID identity and access management (IAM) platform that has been exploited in attacks. [...]

security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

Microsoft rolls out Classic Outlook theme for New Outlook users

Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]

ai

OpenAI Adds Controls That Should've Been There Already

The new AI security controls follow the Hugging Face incident last month, though many of these additions perhaps should have been in place prior to the frontier models escaping.