Cybersecurity
CISA orders federal agencies to patch TrueConf flaws
CISA added two TrueConf Server flaws to its known exploited list and told federal civilian agencies to patch them by 3 September after reports that the vulnerabilities were being used.
- CISA added CVE-2026-72529 and CVE-2026-72530 to its KEV catalogue on Thursday and told U.S. Federal Civilian Executive Branch agencies to secure their servers by 3 September.
- TrueConf Server is a self-hosted messaging and video conferencing platform that runs inside an organisation's local network.
- TrueConf said CVE-2026-72529 allowed a remote unauthenticated attacker on port 4307/TCP to trigger an undocumented function and run a script, while CVE-2026-72530 could lead to remote code execution through code injection and sandbox escape.
- CISA did not publish attack details, but Kaspersky said Head Mare had been exploiting both flaws since at least July 2026 to replace client installers with malicious versions that deployed backdoor malware.
- Check Point Research said in April 2026 that another TrueConf flaw, CVE-2026-3502, had been targeted in zero-day attacks it called Operation True Chaos and linked to Chinese threat actors.
CISA added the two flaws to its KEV list on Thursday and told U.S. Federal Civilian Executive Branch agencies to secure affected servers by 3 September. It said such flaws were a common route for malicious actors and a risk to federal systems.
TrueConf Server is a self-hosted messaging and video conferencing platform that runs inside a local network. TrueConf said CVE-2026-72529 let an unauthenticated attacker use port 4307/TCP to trigger a hidden function and run a script on the server.
The second flaw, CVE-2026-72530, let an unauthenticated attacker use code injection to reach remote code execution, according to TrueConf. The company also said a code-generation problem could let someone who already had code execution leave its isolated environment and run commands on the host operating system.
CISA did not give attack details. Kaspersky said Head Mare had been exploiting both flaws since at least July 2026 to replace client installers with malicious versions that installed backdoor malware, and said the campaigns had hit Russian organisations in transport, energy, IT, electronics and software development.
In April 2026, Check Point Research said attackers were using CVE-2026-3502 in zero-day attacks it named Operation True Chaos and tied to Chinese threat actors. The article did not say whether that activity was connected to the two flaws CISA later added to its list.
Named in this story
Companies
- TrueConf
- its security team described the flaws
- Kaspersky
- said Head Mare had been exploiting the flaws since at least July 2026
Organisations
- Head Mare
- the hacktivist group Kaspersky linked to the exploitation
- Check Point Research
- reported attacks on another TrueConf flaw in April 2026
Governments and agencies
- U.S. Cybersecurity and Infrastructure Security Agency
- added the flaws to its KEV catalogue and set the patch deadline
- U.S. Federal Civilian Executive Branch
- the agencies ordered to secure affected servers
Products and systems
- TrueConf Server
- the self-hosted communications platform with the vulnerabilities
- CVE-2026-72529
- the missing-authentication flaw that allowed arbitrary script execution
- CVE-2026-72530
- the code-injection flaw that could lead to remote code execution
- CVE-2026-3502
- another TrueConf flaw targeted in zero-day attacks
How the source tells it
The register was a straightforward security report, with urgency and alarm supplied by deadlines, severity labels and warnings about federal risk.
- urgency a two-week remediation deadline and an instruction to prioritise patching
- alarm critical-severity labels and a warning about significant risks to the federal enterprise