The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is sounding the alarm about two critical vulnerabilities in TrueConf Server, which have already gone from theory to practice, as they are being exploited in real cyberattacks. The agency has asked U.S. federal agencies to proceed immediately with the installation of available fixes, emphasizing that these gaps can offer attackers a particularly dangerous path to internal organizational systems.

Two critical vulnerabilities with remote execution capability
TrueConf Server is a corporate communication platform for messaging, voice calls , and video conferencing. Unlike popular cloud services like Zoom and Microsoft Teams, it can be installed and operated within an organization's infrastructure, on its local network.
This architecture offers greater control over data, but it also creates an additional target for cybercriminals. If an internal server is compromised, the attacker can gain access to critical services or attempt lateral movement in the network.
See also: Cisco Crosswork & Secure Workload: Critical Vulnerabilities – Immediate Update
The more serious of the two vulnerabilities is CVE-2026-72529, which is related to insufficient authentication. A remote attacker, without an account or other privileges, can communicate with the server via port 4307/TCP and enable undocumented functionality to execute arbitrary scripts.
Simply put, this vulnerability could allow an attacker to execute commands on a vulnerable server without first having to log in as a legitimate user.
The second vulnerability could lead to a full breach
Even more concerning is CVE-2026-72530, also rated critical. Exploiting it requires a more complex technical attack via injection into the code generation mechanism, but the result can be particularly serious.
According to TrueConf, an attacker who has managed to execute code within the isolated server environment can attempt a sandbox escape. If the attempt is successful, the attacker can exit the restricted environment and gain the ability to execute arbitrary commands on the underlying operating system.
This turns an initial penetration into a potential launching point for a broader attack.
CISA puts TrueConf on the KEV list
CISA added the two vulnerabilities to its Known Exploited Vulnerabilities (KEV), a move that signals that the flaws are not just theoretical threats. U.S. federal agencies have been given until September 3, 2026 , to implement the necessary fixes.
See also: Cudy WR3000: Critical CVE chain with public PoC — Dangerous for Greek holders
Inclusion on the KEV list is a significant red flag for organizations outside the US as well, as it indicates that there is active interest from attackers and that delaying patch installation significantly increases exposure.

Head Mare team in the spotlight
Although CISA did not provide details about the attacks, Kaspersky has linked the exploitation of the two vulnerabilities to the Head Mare. According to the company, the attacks have been recorded since at least July 2026 and involve replacing legitimate application installers with modified, malicious versions.
These installers are used to install backdoors, essentially opening a hidden access path to infected computers. The group's campaigns have targeted organizations in Russia from diverse industries, including transportation, energy, IT, electronics, and software development.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This is not the first time TrueConf has been targeted
This case is even more serious when you consider that TrueConf has been targeted by attackers in the past. In April 2026, Check Point Research revealed zero-day attacks against another vulnerability, CVE-2026-3502, as part of “OperationTrue Chaos”.
See also: Zimbra vulnerability exploited for remote code execution
The attacks were allegedly linked to Chinese groups cyberespionage and exploited infected app updates.
The new incident is a reminder that on-premise communication platforms need the same rigorous treatment as any other critical business system. Promptly installing patches, restricting access to administrative ports, monitoring suspicious installers, and implementing least privilege can significantly reduce the chances of a successful breach.
Source: www.bleepingcomputer.com
