CISA has issued a directive ordering U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in TrueConf Server, a self-hosted communications platform. The vulnerabilities are being actively exploited in the wild, prompting CISA to add them to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies are required to remediate the flaws within a specified deadline under Binding Operational Directive 22-01. TrueConf Server is used for self-hosted video conferencing and team messaging, making it a potentially high-value target. The active exploitation underscores the urgency for both federal and private sector organizations to apply available patches immediately.
Two critical vulnerabilities affect TrueConf Server, a self-hosted corporate messaging and video conferencing platform that operates within an organization's LAN. CVE-2026-72529 is a missing authentication flaw that allows a remote unauthenticated attacker connecting over port 4307/TCP to invoke an undocumented critical function and execute arbitrary scripts on the server. CVE-2026-72530 is a sandbox escape via code injection; improper management of code generation allows an attacker who has achieved code execution within TrueConf Server's isolated environment to escape the sandbox and execute arbitrary commands on the underlying operating system. Both vulnerabilities have been actively exploited since at least July 2026 by the Head Mare hacktivist group, which replaced legitimate TrueConf client installers with trojanized versions deploying backdoor malware. A separate zero-day flaw (CVE-2026-3502) in TrueConf was also exploited in 'Operation True Chaos' by Chinese threat actors via trojanized client updates, as reported by Check Point Research in April 2026.
1. U.S. Federal Civilian Executive Branch (FCEB) agencies must patch TrueConf Server by September 3 per CISA's KEV catalog directive. 2. All organizations running TrueConf Server should apply the latest security patches immediately as published by TrueConf. 3. Review TrueConf security advisories at https://trueconf.com/blog/news/security-fixes-updates-and-advisories for patch details. 4. Monitor network traffic for unexpected connections to TrueConf Server on TCP port 4307. 5. Verify integrity of TrueConf client installers and software update packages to detect trojanization. 6. Investigate any signs of sandbox escape or unauthorized code execution on TrueConf Server hosts. 7. Check for indicators of backdoor malware deployment on systems that received TrueConf client updates. 8. Restrict access to TrueConf Server to authorized internal users and network segments only.
Network: Suspicious inbound connections to TrueConf Server on TCP port 4307, Trojanized TrueConf client installers containing backdoor malware, Modified/replaced TrueConf client software update packages