CISA orders feds to patch actively exploited TrueConf Server flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert to all federal agencies, instructing them to patch two critical vulnerabilities in the TrueConf Server self-hosted communications platform as soon as possible. These flaws, which allow attackers to remotely execute arbitrary scripts and gain code execution on vulnerable servers, have already been exploited by malicious hackers.

TrueConf Server is used for secure corporate messaging and video conferencing within an organization’s local network (LAN). Unlike cloud-based software like Zoom or Microsoft Teams, it operates directly within the company’s internal systems. The two vulnerabilities in question are a critical missing authentication security flaw (CVE-2026-72529) and another critical severity vulnerability (CVE-2026-72530), both of which can be exploited by unauthenticated attackers through high-complexity code injection attacks.

According to TrueConf, the most severe vulnerability (CVE-2026-72529) allows attackers to remotely invoke an undocumented critical function on an unpatched server, effectively granting them arbitrary script execution capabilities. The second flaw (CVE-2026-72530) enables threat actors to inject malicious code into the TrueConf Server environment, potentially allowing them to escape the sandbox and execute arbitrary commands on the underlying operating system.

CISA has added these vulnerabilities to its KEV catalog and ordered US Federal Civilian Executive Branch (FCEB) agencies to secure their servers within two weeks. This move is likely a response to reports that hackers have been actively exploiting these flaws in recent attacks. Cybersecurity company Kaspersky has confirmed that the Head Mare hacktivist group has been using CVE-2026-72529 and CVE-2026-72530 since at least July 2026, targeting Russian organizations across various industry sectors.

The exploitation of these vulnerabilities highlights the importance of timely patching and security updates. In fact, CISA’s warning emphasizes that this type of vulnerability is a frequent attack vector for malicious actors and poses significant risks to federal systems. By acting quickly to address these flaws, agencies can minimize their exposure to potential attacks and protect sensitive data.

In practical terms, this alert serves as a reminder to all organizations – not just federal agencies – to regularly review their software configurations and ensure that they are up-to-date with the latest security patches. This is especially crucial for self-hosted platforms like TrueConf Server, which require manual updates and monitoring. By staying vigilant and proactive in addressing known vulnerabilities, we can reduce our collective risk of falling victim to these types of attacks.


Source: Bleeping Computer — 2026-08-21