TL;DR
CISA added two TrueConf Server flaws to its Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-72529 and CVE-2026-72530, both are exploited in the wild. Attackers chain them to run code and plant PhantomCore malware. Fixed versions have shipped.
- Product: TrueConf Server
- Vulnerabilities: 2 flaws (CVE-2026-72529, CVE-2026-72530)
- Highest severity: 9.8 (Critical · CVSSv3)
- Worst impact: A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server...
- Status: 2 exploited; patches available
- Action: Update to 5.3, 5.3.9, 5.4.9, 5.5.5 now
| CVE | CVSS (CVSSv3) | Fixed in | Status |
|---|---|---|---|
| CVE-2026-72529 | 9.8 | 5.3, 5.3.9, 5.4.9 (+1) | Exploited |
| CVE-2026-72530 | 9 | 5.3, 5.3.9, 5.4.9 (+1) | Exploited |
Why It Matters
TrueConf is a widely used video conferencing and communications platform. A server breach here reaches far beyond one company. Kaspersky warns that even organizations without a TrueConf server face risk.
Staff who join a contractor’s compromised server can download a poisoned installer. That makes this exploited in the wild campaign a supply chain threat. Both flaws score critical, at 9.3 and 9.5.
How the Attack Works
The two bugs work as a chain, reached over TCP port 4307. That port is open by default, per TrueConf documentation. No authentication is needed to connect.
CVE-2026-72529 lets an attacker run a script by calling an undocumented function. That script starts in an isolated sandbox. CVE-2026-72530 then breaks out of that sandbox to run code on the host. Kaspersky ties the activity to the Head Mare group.
From Server to Client
After the break-out, attackers plant a web shell and swap the client installer. Conference participants are then prompted to download a fresh client. That installer drops the PhantomCore backdoor, giving attackers control of the endpoint. Kaspersky documents the chain in its TrueConf threat report.
Affected Versions
The flaws affect TrueConf Server 5.3.x to 5.3.9, 5.4.x to 5.4.9, 5.5.x to 5.5.5, and earlier. Kaspersky’s analysis suggests all versions since 2022 are vulnerable. No public install count is available.
Patch and Mitigation Steps
Update TrueConf Server to 5.3.9, 5.4.9, or 5.5.5 right away. The vendor released these fixes on June 18, 2026. Federal agencies must act under the CISA KEV directive.
After patching, hunt for indicators of compromise on servers and endpoints. Run a full antivirus scan with current signatures. If you joined a TrueConf meeting recently, check your workstation for a tampered client too.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.