CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

US Cybersecurity Agency Warns of Active Attacks on TrueConf Video Conferencing Platform

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning to federal agencies, urging them to immediately patch two critical vulnerabilities in the popular video conferencing platform, TrueConf. The agency has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating that they have been actively exploited by hackers.

TrueConf is a secure on-premises video conferencing platform used by organizations worldwide. It relies on Scalable Video Coding (SVC) to connect client applications through a dedicated corporate server. However, since 2022, all versions of TrueConf Server have contained two critical-severity bugs tracked as CVE-2026-72529 and CVE-2026-72530. These vulnerabilities allow attackers to execute arbitrary code on the affected system.

The exploited flaws can be accessed remotely via port 4307/TCP. According to CISA, CVE-2026-72529 allows an attacker to call an undocumented function and execute arbitrary scripts, while CVE-2026-72530 enables them to escape the isolated environment and execute scripts on the host system. These vulnerabilities were addressed in June 2026, but the warning from CISA indicates that hackers have already begun exploiting them.

The hacktivist group Head Mare has been linked to these attacks, using the exploited TrueConf vulnerabilities to deploy the PhantomCore malware. According to Kaspersky, an earlier investigation revealed that the attackers had compromised an organization’s TrueConf server by replacing one of its files with a web shell. This web shell was used to gather information about the IT infrastructure of the attacked organization, gain privileged access to the TrueConf Server database, and replace legitimate client installers.

Once executed on employee systems, these malicious installers installed PhantomCore malware, which is typically associated with Head Mare’s intrusions. The attackers also installed backdoors on affected *nix servers running TrueConf, using the TrueConf protocol for command-and-control (C&C) communication. Another backdoor was installed on *nix systems, utilizing GitHub.

Given the high-risk nature of these vulnerabilities and their active exploitation by hackers, CISA is urging federal agencies to take immediate action. TrueConf server owners are advised to update to a patched version, scan their environments for indicators of compromise (IoCs), scan for malicious artifacts, and rotate credentials for all potentially affected accounts if an intrusion is detected.

The warning from CISA serves as a stark reminder that even seemingly secure platforms can be vulnerable to exploitation by hackers. It highlights the importance of regular security updates, thorough scanning for vulnerabilities, and prompt action in response to warnings from cybersecurity agencies. In this case, it’s crucial for organizations using TrueConf to take immediate action to patch these vulnerabilities and protect their systems from potential attacks.


Source: SecurityWeek — 2026-08-21