The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert to federal agencies, ordering them to patch two critical vulnerabilities in the TrueConf Server self-hosted communications platform as soon as possible. These flaws have been actively exploited by hackers, putting sensitive information and systems at risk.
TrueConf Server is used by organizations for secure corporate messaging and video conferencing, but unlike cloud-based platforms like Zoom or Microsoft Teams, it operates within an organization’s local network (LAN). The two vulnerabilities in question are a missing authentication security flaw, tracked as CVE-2026-72529, which allows attackers to remotely execute arbitrary scripts on unpatched servers without any privileges. The second vulnerability, CVE-2026-72530, is another critical severity flaw that enables threat actors to exploit high-complexity code injection attacks and gain remote code execution.
In a statement, the TrueConf security team explained that the first vulnerability allows an attacker connecting to the server over port 4307/TCP to invoke an undocumented critical function and execute an arbitrary script on the server. The second flaw is described as “improper management of code generation,” which can allow attackers who have achieved code execution in the isolated environment to escape the sandbox and execute arbitrary commands on the underlying operating system.
The CISA has added these two flaws to its KEV catalog, which lists known exploited vulnerabilities that pose a significant risk to federal agencies. The agency has ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure their servers within two weeks, by September 3. This is not an idle warning – the cybersecurity agency emphasized that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Security company Kaspersky has reported that the Head Mare hacktivist group has been exploiting these vulnerabilities since at least July 2026, targeting Russian organizations across various industry sectors. The hackers replaced client installers with malicious versions designed to deploy backdoor malware. This is not an isolated incident – in April 2026, Check Point Research reported a zero-day attack dubbed “Operation True Chaos” linked to Chinese threat actors, compromising users via trojanized client updates.
The takeaway from this alert is clear: if you’re using TrueConf Server, patching these vulnerabilities as soon as possible should be your top priority. The risks are real and the consequences of delay could be severe. In addition to keeping software up-to-date, organizations should also consider implementing additional security measures, such as monitoring for suspicious activity and regularly testing their defenses against potential threats. By staying vigilant and proactive, you can help protect your organization from these types of attacks.
Source: Bleeping Computer — 2026-08-21