US Cybersecurity Agency Warns of Critical TrueConf Server Flaws Under Active Attack
A serious vulnerability in popular video conferencing platform TrueConf has been exploited by hackers, prompting the US cybersecurity agency CISA to urge federal agencies to patch the issue immediately. The warning highlights the urgent need for organizations to address this critical flaw before it’s too late.
TrueConf is a secure on-premises video conferencing solution that relies on Scalable Video Coding (SVC) to connect client applications through a dedicated corporate server. However, two critical-severity bugs in all TrueConf Server versions since 2022 have been exploited by attackers. The vulnerabilities, tracked as CVE-2026-72529 and CVE-2026-72530, allow remote attackers with access to the TrueConf server via port 4307/TCP to execute arbitrary code.
The two flaws work differently but share a common goal: allowing attackers to bypass security controls and gain unauthorized access to the system. CVE-2026-72529 enables the attacker to call an undocumented function and execute arbitrary scripts, while CVE-2026-72530 allows them to escape the isolated environment and execute scripts on the host system.
The exploited vulnerabilities were patched in June 2026, but it appears that many organizations have yet to apply the fix. CISA’s warning is a clear indication that this vulnerability has been actively exploited by hackers. The agency added both flaws to its Known Exploited Vulnerabilities (KEV) catalog and urged federal agencies to patch CVE-2026-72529 within three days and CVE-2026-72530 within two weeks.
The hacking group Head Mare, known for targeting organizations in Russia and Belarus with destructive attacks, has been linked to the exploitation of these vulnerabilities. According to Kaspersky, the hackers used the flaws to compromise an organization’s TrueConf server, replace a file with a web shell, and deploy the PhantomCore malware on employees’ systems.
The aftermath of such an attack can be devastating for organizations. The compromised system becomes a launching pad for further attacks, allowing the attackers to gather information about the IT infrastructure, gain privileged access to sensitive data, and even demand ransom payments from victims.
To mitigate this risk, TrueConf server owners are advised to update their systems to patched versions, scan for indicators of compromise (IoCs), and rotate credentials for all affected accounts if an intrusion is detected. This timely warning serves as a reminder that cybersecurity threats can emerge at any moment, and it’s crucial for organizations to stay vigilant and proactive in addressing vulnerabilities before they’re exploited.
In light of this incident, it’s essential for security teams to prioritize patching and vulnerability management. Regularly updating software and systems, combined with robust threat detection and response measures, can help prevent such attacks from succeeding. By staying informed about emerging threats and taking swift action, organizations can safeguard their networks and protect sensitive data from malicious actors.
Source: SecurityWeek — 2026-08-21