US civilian federal agencies face a remediation deadline for two actively exploited TrueConf Server vulnerabilities that attackers have used to compromise the video conferencing platform and distribute malware, according to CISA and Kaspersky.
The Cybersecurity and Infrastructure Security Agency added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence that attackers are exploiting both flaws in the wild.
CVE-2026-72529 is a missing-authentication flaw that carries a CVSS score of 9.8 in TrueConf’s security advisory. A remote attacker who can reach TrueConf Server over TCP port 4307 can invoke an undocumented function and run an arbitrary script without authentication.
CVE-2026-72530 is a critical code-injection and sandbox-escape vulnerability with a CVSS score of 9.0. An attacker who has gained code execution inside TrueConf’s isolated environment can escape the sandbox and execute commands on the underlying operating system, according to TrueConf.
Why CISA is sounding the alarm
CISA said vulnerabilities in its KEV Catalog are frequently used by malicious cyber actors and pose significant risks to federal networks.
Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must remediate covered vulnerabilities by CISA’s specified deadlines. The directive also sets expectations for determining whether a system was compromised before a patch was installed.
Although the directive applies to federal agencies, CISA encourages private organizations to use the KEV Catalog as part of their own risk-based vulnerability management programs.
Attackers turned servers into malware delivery points
The danger may extend beyond organizations running vulnerable servers.
Kaspersky has linked exploitation of the two flaws to the Head Mare hacktivist group, which targeted Russian organizations in sectors including transportation, energy, IT, electronics and software development. Attackers used compromised TrueConf servers to replace legitimate client installers with trojanized versions carrying the PhantomCore backdoor.
That creates a supply-chain risk because users who download a TrueConf client from a compromised server may receive the trojanized package instead of the legitimate software.
Remediation and operational next steps
CISA encourages private organizations to prioritize KEV vulnerabilities in their vulnerability management programs. TrueConf Server administrators should apply the vendor’s fixed releases and investigate exposed systems for signs of compromise.
Organizations managing large patch queues can follow the same risk-based approach used for Microsoft’s August Patch Tuesday, putting actively exploited and internet-facing vulnerabilities ahead of lower-risk flaws.
Administrators should:
- Update TrueConf Server deployments to versions 5.3.9, 5.4.9, 5.5.5, or later.
- Restrict or block inbound external network access to default TCP port 4307.
- Audit server file integrity to verify client installers have not been replaced.
- Inspect systems for unauthorized web shells, review host logs for active indicators of compromise, and cycle credentials across associated database services if unauthorized access is suspected.
Administrators should treat this as both a patching task and a potential incident-response exercise. If a TrueConf server was exposed before remediation, teams should verify the server’s integrity and inspect its downloadable client installers rather than assuming that installing the update removed evidence of an earlier compromise.
Read more: Learn how AI is reshaping software supply-chain risk and why organizations must look beyond conventional vulnerability patching to protect trusted software channels.





