CISA Orders Civilian Agencies to Patch Exploited TrueConf Server Flaws

CISA ordered civilian agencies to patch two exploited TrueConf Server flaws used to compromise systems and distribute trojanized client installers.

Aug 24, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

US civilian federal agencies face a remediation deadline for two actively exploited TrueConf Server vulnerabilities that attackers have used to compromise the video conferencing platform and distribute malware, according to CISA and Kaspersky.

The Cybersecurity and Infrastructure Security Agency added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence that attackers are exploiting both flaws in the wild.

CVE-2026-72529 is a missing-authentication flaw that carries a CVSS score of 9.8 in TrueConf’s security advisory. A remote attacker who can reach TrueConf Server over TCP port 4307 can invoke an undocumented function and run an arbitrary script without authentication.

CVE-2026-72530 is a critical code-injection and sandbox-escape vulnerability with a CVSS score of 9.0. An attacker who has gained code execution inside TrueConf’s isolated environment can escape the sandbox and execute commands on the underlying operating system, according to TrueConf

Why CISA is sounding the alarm

CISA said vulnerabilities in its KEV Catalog are frequently used by malicious cyber actors and pose significant risks to federal networks.

Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must remediate covered vulnerabilities by CISA’s specified deadlines. The directive also sets expectations for determining whether a system was compromised before a patch was installed.

Although the directive applies to federal agencies, CISA encourages private organizations to use the KEV Catalog as part of their own risk-based vulnerability management programs.

Attackers turned servers into malware delivery points

The danger may extend beyond organizations running vulnerable servers.

Kaspersky has linked exploitation of the two flaws to the Head Mare hacktivist group, which targeted Russian organizations in sectors including transportation, energy, IT, electronics and software development. Attackers used compromised TrueConf servers to replace legitimate client installers with trojanized versions carrying the PhantomCore backdoor.

Advertisement

That creates a supply-chain risk because users who download a TrueConf client from a compromised server may receive the trojanized package instead of the legitimate software.

Remediation and operational next steps

CISA encourages private organizations to prioritize KEV vulnerabilities in their vulnerability management programs. TrueConf Server administrators should apply the vendor’s fixed releases and investigate exposed systems for signs of compromise.

Organizations managing large patch queues can follow the same risk-based approach used for Microsoft’s August Patch Tuesday, putting actively exploited and internet-facing vulnerabilities ahead of lower-risk flaws.

Administrators should:

  • Update TrueConf Server deployments to versions 5.3.9, 5.4.9, 5.5.5, or later.
  • Restrict or block inbound external network access to default TCP port 4307.
  • Audit server file integrity to verify client installers have not been replaced.
  • Inspect systems for unauthorized web shells, review host logs for active indicators of compromise, and cycle credentials across associated database services if unauthorized access is suspected.

Administrators should treat this as both a patching task and a potential incident-response exercise. If a TrueConf server was exposed before remediation, teams should verify the server’s integrity and inspect its downloadable client installers rather than assuming that installing the update removed evidence of an earlier compromise.

Read more: Learn how AI is reshaping software supply-chain risk and why organizations must look beyond conventional vulnerability patching to protect trusted software channels.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.