CISA orders feds to patch actively exploited TrueConf Server flaws
Reported exploitedTrueConf ServerHead MareOur summary
CISA has directed U.S. federal agencies to remediate two critical vulnerabilities in TrueConf Server, which are currently under active exploitation in the wild. The first flaw, CVE-2026-72529, permits unauthenticated remote code execution via an undocumented function on port 4307/TCP, while CVE-2026-72530 enables a sandbox escape through complex code injection. Kaspersky identifies the hacktivist group Head Mare as the actor leveraging these weaknesses since July 2026 to distribute trojanized client installers containing backdoor malware, primarily targeting Russian organizations. Federal civilian executive branch agencies must complete patches by September 3.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.