The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to immediately patch two critical vulnerabilities in the TrueConf Server self-hosted communications platform, which are reportedly being actively exploited in the wild. The directive, issued on Thursday, August 21, 2026, requires all U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their systems by September 3, 2026.
TrueConf Server is a platform designed for secure corporate messaging and video conferencing, operating within an organization's local network rather than as a cloud-based service. CISA emphasized that vulnerabilities of this nature are frequently targeted by malicious actors and present substantial risks to federal systems.
The first vulnerability, tracked as CVE-2026-72529, is a critical missing authentication flaw. It allows an unauthenticated remote attacker to execute arbitrary scripts on unpatched servers by connecting to TrueConf Server over TCP port 4307 and invoking an undocumented critical function. TrueConf's security team confirmed this issue, stating that it enables attackers without privileges to perform remote script execution.
The second vulnerability, CVE-2026-72530, is also rated as critical and involves improper management of code generation. This flaw can be exploited by unauthenticated threat actors through high-complexity code injection attacks. According to TrueConf, an attacker who has achieved code execution within the TrueConf Server's isolated environment can escape this sandbox and execute arbitrary commands on the underlying operating system.
While CISA did not disclose specific details regarding the ongoing exploitation, cybersecurity firm Kaspersky has claimed that a hacktivist group named "Head Mare" has been leveraging both CVE-2026-72529 and CVE-2026-72530 since at least July 2026. The group allegedly uses these vulnerabilities to replace legitimate client installers with malicious versions designed to deploy backdoor malware. Kaspersky reported that multiple Head Mare campaigns have targeted Russian organizations across various sectors, including transportation, energy, IT, electronics, and software development.
These recent advisories follow an earlier report in April 2026 by Check Point Research, which detailed "Operation True Chaos." This campaign involved Chinese threat actors exploiting another TrueConf flaw, CVE-2026-3502, in zero-day attacks to compromise users through trojanized client updates.






