Skip to main content

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

0
Medium
Vulnerabilitymalware
Published: 08/21/2026 (08/21/2026, 07:25:50 UTC)
Source: SecurityWeek

Description

The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek .

Affected software

Affected versions
>=2022 <5.3.9

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/21/2026, 07:37:28 UTC

Technical Analysis

TrueConf Server, an on-premises video conferencing platform, contains two critical remote code execution vulnerabilities (CVE-2026-72529 and CVE-2026-72530) present in all versions since 2022. CVE-2026-72529 allows calling an undocumented function to execute arbitrary scripts, while CVE-2026-72530 enables escaping the isolated environment to execute scripts on the host system. Both vulnerabilities can be exploited remotely via TCP port 4307. The hacktivist group Head Mare has exploited these bugs to deploy PhantomCore malware by compromising the TrueConf server, replacing files with web shells, gathering infrastructure information, gaining privileged database access, and distributing malicious client installers. Backdoors were also installed on Unix-based servers using the TrueConf protocol and GitHub for C&C. The vulnerabilities were fixed in TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5 released in June 2026. CISA has added these to its KEV catalog and recommends urgent patching.

Potential Impact

Exploitation of these vulnerabilities allows remote attackers to execute arbitrary code on the TrueConf server, escape isolated environments, and gain privileged access to the server's database. This enables attackers to deploy malware (PhantomCore), install backdoors for persistent access, replace legitimate client installers with malicious versions, and gather sensitive information about the victim's IT infrastructure. The attacks have been observed targeting organizations in Russia and Belarus, causing destructive impacts and ransomware demands, although the threat actor is not financially motivated.

Mitigation Recommendations

A fix is available: TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5 released in June 2026 address these vulnerabilities. CISA urges immediate patching, recommending that federal agencies patch CVE-2026-72529 within three days and CVE-2026-72530 within two weeks. Server owners should update to these patched versions, scan their environments for indicators of compromise and malicious artifacts, and rotate credentials for all potentially affected accounts if an intrusion is detected.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.8,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-trueconf-vulnerabilities/","fetched":true,"fetchedAt":"2026-08-21T07:37:10.598Z","wordCount":1121}

Threat ID: 6a880026acd9273b49c6efb1

Added to database: 08/21/2026, 07:37:10 UTC

Last enriched: 08/21/2026, 07:37:28 UTC

Last updated: 10/03/2026, 18:22:59 UTC

Views: 125

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses