The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has mandated that federal agencies patch two actively exploited vulnerabilities in TrueConf Server, a video conferencing platform developed in Russia. The flaws, identified as CVE-2026-72529 and CVE-2026-72530, were added to CISA's Known Exploited Vulnerabilities catalog on Thursday, indicating their use in real-world attacks. Federal agencies are required to apply the patches by September 10.
TrueConf, based in Moscow, offers on-premises video conferencing solutions, allowing organizations to host the server on their own infrastructure, including private networks. While the company's primary customer base is in Russia, it has a global user presence, including entities like Switzerland’s Department of Justice and Home Affairs and Istanbul Airport.
Security researchers have linked the exploitation of these vulnerabilities to Head Mare, a pro-Ukrainian hacktivist group. This group has previously targeted Russian organizations across various sectors, including transport, energy, electronics, IT, and software development. The latest campaign reportedly involved compromising TrueConf servers to distribute malware to meeting participants.
The two vulnerabilities, when chained together, allow an attacker to gain control of the underlying server. CVE-2026-72529 enables an unauthenticated attacker with network access to TCP port 4307, which TrueConf documentation states is open by default, to execute a malicious script. CVE-2026-72530 then allows the attacker to escape the isolated environment of the script and execute arbitrary code on the server.
In observed attacks, Head Mare exploited this access to install a web shell, move laterally within the victim's infrastructure, and obtain privileged access to the TrueConf database. Attackers then replaced the legitimate TrueConf Windows client installer on compromised servers with a trojanized version containing the PhantomCore backdoor.
This method of attack poses a risk not only to organizations directly running vulnerable TrueConf servers but also to employees who join conferences hosted by third parties. Such individuals could inadvertently download a compromised client from a hacked server belonging to a supplier or partner.
TrueConf released fixes for these vulnerabilities on June 18 in versions 5.3.9, 5.4.9, and 5.5.5. The company warned customers that failing to update could leave their conferencing systems exposed to attacks over the public internet. The flaws affect TrueConf Server releases dating back to 2022.
While exploitation requires network access to the vulnerable service, meaning servers confined to internal networks would not be directly reachable from the outside without an initial breach, the potential for malware distribution through compromised client installers highlights the broader risk.






