HomeSecurityVulnerabilities in TrueConf Server: CISA requests immediate patching

Vulnerabilities in TrueConf Server: CISA requests immediate patching

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is sounding the alarm about two critical vulnerabilities in TrueConf Server, which have already gone from theory to practice, as they are being exploited in real cyberattacks. The agency has asked U.S. federal agencies to proceed immediately with the installation of available fixes, emphasizing that these gaps can offer attackers a particularly dangerous path to internal organizational systems.

TrueConf Server

Two critical vulnerabilities with remote execution capability

TrueConf Server is a corporate communication platform for messaging, voice calls , and video conferencing. Unlike popular cloud services like Zoom and Microsoft Teams, it can be installed and operated within an organization's infrastructure, on its local network.

This architecture offers greater control over data, but it also creates an additional target for cybercriminals. If an internal server is compromised, the attacker can gain access to critical services or attempt lateral movement in the network.

See also: Cisco Crosswork & Secure Workload: Critical Vulnerabilities – Immediate Update

The more serious of the two vulnerabilities is CVE-2026-72529, which is related to insufficient authentication. A remote attacker, without an account or other privileges, can communicate with the server via port 4307/TCP and enable undocumented functionality to execute arbitrary scripts.

Simply put, this vulnerability could allow an attacker to execute commands on a vulnerable server without first having to log in as a legitimate user.

The second vulnerability could lead to a full breach

Even more concerning is CVE-2026-72530, also rated critical. Exploiting it requires a more complex technical attack via injection into the code generation mechanism, but the result can be particularly serious.

According to TrueConf, an attacker who has managed to execute code within the isolated server environment can attempt a sandbox escape. If the attempt is successful, the attacker can exit the restricted environment and gain the ability to execute arbitrary commands on the underlying operating system.

This turns an initial penetration into a potential launching point for a broader attack.

CISA puts TrueConf on the KEV list

CISA added the two vulnerabilities to its Known Exploited Vulnerabilities (KEV), a move that signals that the flaws are not just theoretical threats. U.S. federal agencies have been given until September 3, 2026 , to implement the necessary fixes.

See also: Cudy WR3000: Critical CVE chain with public PoC — Dangerous for Greek holders

Inclusion on the KEV list is a significant red flag for organizations outside the US as well, as it indicates that there is active interest from attackers and that delaying patch installation significantly increases exposure.

Vulnerabilities in TrueConf Server: CISA requests immediate patching

Head Mare team in the spotlight

Although CISA did not provide details about the attacks, Kaspersky has linked the exploitation of the two vulnerabilities to the Head Mare. According to the company, the attacks have been recorded since at least July 2026 and involve replacing legitimate application installers with modified, malicious versions.

These installers are used to install backdoors, essentially opening a hidden access path to infected computers. The group's campaigns have targeted organizations in Russia from diverse industries, including transportation, energy, IT, electronics, and software development.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This is not the first time TrueConf has been targeted

This case is even more serious when you consider that TrueConf has been targeted by attackers in the past. In April 2026, Check Point Research revealed zero-day attacks against another vulnerability, CVE-2026-3502, as part of “OperationTrue Chaos”.

See also: Zimbra vulnerability exploited for remote code execution

The attacks were allegedly linked to Chinese groups cyberespionage and exploited infected app updates.

The new incident is a reminder that on-premise communication platforms need the same rigorous treatment as any other critical business system. Promptly installing patches, restricting access to administrative ports, monitoring suspicious installers, and implementing least privilege can significantly reduce the chances of a successful breach.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS