CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog after reports that attackers were actively abusing them to gain remote code execution on exposed servers. The flaws, tracked as CVE-2026-72529 and CVE-2026-72530, affect TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, and 5.5.x before 5.5.5. According to the advisories, CVE-2026-72529 is a missing-authentication flaw that can let an unauthenticated remote attacker execute arbitrary scripts over 4307/TCP, while CVE-2026-72530 is a code-injection issue that can allow breakout from an isolated environment and arbitrary code execution on the host system.
Kaspersky reported that attackers linked to the Head Mare APT group chained the vulnerabilities to compromise TrueConf servers at Russian organizations, obtain NT AUTHORITY\SYSTEM-level access on Windows hosts, and install web shells and backdoors. The intruders then mapped victim infrastructure, accessed databases, and replaced legitimate TrueConf client downloads with installers bundled with PhantomCore malware, turning meeting joins into an infection path for downstream users. TrueConf issued fixes on June 18 in versions 5.3.9, 5.4.9, and 5.5.5, and government advisories in the United States and Canada urged administrators to review vendor guidance and apply updates immediately because even organizations that do not run TrueConf servers could be exposed through meetings hosted on compromised third-party systems.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
CISA directed Federal Civilian Executive Branch agencies to urgently remediate CVE-2026-72529 and CVE-2026-72530 on affected TrueConf Server systems within two weeks, setting a September 3 deadline. The agency warned the actively exploited flaws pose significant risk to the federal enterprise.
CISA updated its Known Exploited Vulnerabilities catalog on 2026-08-20, adding two TrueConf Server flaws: CVE-2026-72529 and CVE-2026-72530. The catalog count increased from 1671 to 1673 entries, and CISA directed stakeholders to follow vendor mitigations and BOD 26-04 guidance.
The ThreatAft reference says the Head Mare group had been exploiting CVE-2026-72530 since at least July 2026 against Russian organizations. Reported activity included planting web shells, replacing TrueConf client installers with malicious versions, deploying backdoors, and accessing infrastructure and databases.
TrueConf fixed the vulnerabilities later tracked as CVE-2026-72529 and CVE-2026-72530 in TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5. Kaspersky said every TrueConf server version released since 2022 had been vulnerable before these patches.
The Canadian Centre for Cyber Security published advisory AV26-835 warning that TrueConf Server versions 5.3.x before 5.3.9, 5.4.x before 5.4.9, and 5.5.x before 5.5.5 are affected by CVE-2026-72529 and CVE-2026-72530. It urged users and administrators to review vendor guidance and apply updates.
Kaspersky investigated attacks against Russian organizations in which attackers associated with Head Mare exploited two TrueConf server vulnerabilities to gain code execution and full control of servers. The attackers installed web shells and backdoors, mapped infrastructure, accessed databases, and replaced legitimate TrueConf client installers with malware-laced versions that delivered PhantomCore to users joining meetings.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 36 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
12 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcescworld.com
Open sourcetheregister.com
Open sourcebleepingcomputer.com
Open sourceics-cert.kaspersky.com
Open sourcetrueconf.com
Open sourcetrueconf.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.