CVE Tools

CISA orders feds to patch actively exploited TrueConf Server flaws

BleepingComputerBy Sergiu Gatlan

Reported exploitedTrueConf ServerHead Mare

Our summary

CISA has directed U.S. federal agencies to remediate two critical vulnerabilities in TrueConf Server, which are currently under active exploitation in the wild. The first flaw, CVE-2026-72529, permits unauthenticated remote code execution via an undocumented function on port 4307/TCP, while CVE-2026-72530 enables a sandbox escape through complex code injection. Kaspersky identifies the hacktivist group Head Mare as the actor leveraging these weaknesses since July 2026 to distribute trojanized client installers containing backdoor malware, primarily targeting Russian organizations. Federal civilian executive branch agencies must complete patches by September 3.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store