CISA Flags TrueConf Server Vulnerabilities Exploited by Hacktivists, Urges Urgent Patch and Mitigation

August 21, 2026
CISA Flags TrueConf Server Vulnerabilities Exploited by Hacktivists, Urges Urgent Patch and Mitigation
  • CISA added two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, to the Known Exploited Vulnerabilities (KEV) catalog after real-world use, including activity by the Head Mare hacktivist group targeting U.S. and Russian entities.

  • The vulnerabilities were linked to active exploitation and to Threat Actor activity, with August 20, 2026, marking their entry into the KEV list.

  • Mitigation steps emphasize isolating affected servers, updating to fixed versions, restricting vulnerable ports (notably 4307), rotating credentials, and conducting cross-device investigations.

  • TrueConf released patches addressing the flaws in versions 5.3.9, 5.4.9, and 5.5.5, warning that missing updates leaves systems exposed and that exploitation requires direct network access to the vulnerable service; isolated networks reduce risk.

  • investigators look for indicators such as locale.php edits, altered installers, web shells, suspicious services, GitHub C2 traffic, and anomalous TrueConf protocol activity.

  • Initial compromise involved web shell deployment, locale.php tampering, and privileged access to the TrueConf database, enabling broader control and persistence.

  • MITRE ATT&CK mappings show a multi-stage intrusion—Exploit Public-Facing Application, Web Shell, Software Supply Chain, and Windows Service creation—driven by supply-chain compromise and post-exploitation moves.

  • CVE-2026-72529 is a remote code execution flaw allowing unauthenticated network access to port 4307 to run scripts; CVE-2026-72530 enables code injection to escape the sandbox and achieve OS-level execution, potentially installing PhantomCore via trojanized installers.

  • Together, the flaws enable an attacker to first execute malicious scripts and then break out of the restricted environment to compromise the TrueConf server.

  • On-premises deployments can spread intra- and inter-organizationally through trusted update channels, raising risks to admins, SOCs, and end users with post-installation behavior and credential integrity concerns.

  • TrueConf describes the first flaw as exploitable by an unauthenticated attacker connecting to port 4307/TCP to invoke an undocumented function and run arbitrary scripts.

  • Attack success hinges on reachable vulnerable servers, chaining the CVEs, installer tampering, and infected participant devices updating with PhantomCore.

Summary based on 4 sources


Get a daily email with more Tech stories

More Stories