CISA urges TrueConf users to patch flaws linked to malware delivery attacks
US federal agencies have been told to update TrueConf Server after two vulnerabilities in the Russian-developed videoconferencing platform were added to the Cybersecurity and Infrastructure Security A...
US federal agencies have been told to update TrueConf Server after two vulnerabilities in the Russian-developed videoconferencing platform were added to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog.
CISA listed CVE-2026-72529 and CVE-2026-72530 on Thursday, identifying both as having been exploited in attacks. The agency did not disclose which organizations were targeted or whether the action was prompted by incidents involving US entities.
The attacks publicly associated with the flaws have been attributed by Kaspersky to Head Mare, a pro-Ukrainian hacktivist group known for targeting Russian organizations. The reported victims included companies in transportation, energy, electronics, information technology and software development.
Server compromise and poisoned installers
According to Kaspersky, an attacker who can reach TrueConf’s service on TCP port 4307 can exploit the first vulnerability without authenticating and execute a script. The second issue can then be used to escape the script’s restricted environment and run code on the host server.
In the documented attacks, the intruders installed a web shell, expanded their access inside victim networks and obtained elevated privileges in the TrueConf database. They also replaced the genuine Windows client installer hosted on compromised systems with a modified package containing the PhantomCore backdoor.
That activity could expose people who do not operate TrueConf themselves. Users joining meetings hosted by business partners or other outside organizations may be prompted to obtain software from a server that has been compromised.
Updates and exposure
Kaspersky said the affected product line includes TrueConf Server releases dating back to 2022. TrueConf issued patched builds—5.3.9, 5.4.9 and 5.5.5—on June 18 and warned that internet-accessible deployments could be attacked if left unupdated.
Direct exploitation still requires network connectivity to the vulnerable service. Systems restricted to an internal network are not directly reachable from the public internet, although they could remain at risk if attackers gain access through another route.
US federal agencies must complete remediation by September 10. Other organizations using TrueConf should apply the vendor updates, review server exposure and check hosted installers and systems for signs of tampering.
