CISA Flags TrueConf Server Vulnerabilities Exploited by Hacktivists, Urges Urgent Patch and Mitigation
August 21, 2026
CISA added two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, to the Known Exploited Vulnerabilities (KEV) catalog after real-world use, including activity by the Head Mare hacktivist group targeting U.S. and Russian entities.
The vulnerabilities were linked to active exploitation and to Threat Actor activity, with August 20, 2026, marking their entry into the KEV list.
Mitigation steps emphasize isolating affected servers, updating to fixed versions, restricting vulnerable ports (notably 4307), rotating credentials, and conducting cross-device investigations.
TrueConf released patches addressing the flaws in versions 5.3.9, 5.4.9, and 5.5.5, warning that missing updates leaves systems exposed and that exploitation requires direct network access to the vulnerable service; isolated networks reduce risk.
investigators look for indicators such as locale.php edits, altered installers, web shells, suspicious services, GitHub C2 traffic, and anomalous TrueConf protocol activity.
Initial compromise involved web shell deployment, locale.php tampering, and privileged access to the TrueConf database, enabling broader control and persistence.
MITRE ATT&CK mappings show a multi-stage intrusion—Exploit Public-Facing Application, Web Shell, Software Supply Chain, and Windows Service creation—driven by supply-chain compromise and post-exploitation moves.
CVE-2026-72529 is a remote code execution flaw allowing unauthenticated network access to port 4307 to run scripts; CVE-2026-72530 enables code injection to escape the sandbox and achieve OS-level execution, potentially installing PhantomCore via trojanized installers.
Together, the flaws enable an attacker to first execute malicious scripts and then break out of the restricted environment to compromise the TrueConf server.
On-premises deployments can spread intra- and inter-organizationally through trusted update channels, raising risks to admins, SOCs, and end users with post-installation behavior and credential integrity concerns.
TrueConf describes the first flaw as exploitable by an unauthenticated attacker connecting to port 4307/TCP to invoke an undocumented function and run arbitrary scripts.
Attack success hinges on reachable vulnerable servers, chaining the CVEs, installer tampering, and infected participant devices updating with PhantomCore.
Summary based on 4 sources
Get a daily email with more Tech stories
Sources

DEV Community • Aug 22, 2026
TrueConf Server Exploitation: PhantomCore Delivered via CVE-2026-72529 / 72530
Security Affairs • Aug 21, 2026
U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog
BleepingComputer • Aug 21, 2026
CISA orders feds to patch actively exploited TrueConf Server flaws
theregister • Aug 21, 2026
Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it