ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

CISA orders federal agencies to patch TrueConf flaws

CISA added two TrueConf Server flaws to its known exploited list and told federal civilian agencies to patch them by 3 September after reports that the vulnerabilities were being used.

BleepingComputer

CISA added the two flaws to its KEV list on Thursday and told U.S. Federal Civilian Executive Branch agencies to secure affected servers by 3 September. It said such flaws were a common route for malicious actors and a risk to federal systems.

TrueConf Server is a self-hosted messaging and video conferencing platform that runs inside a local network. TrueConf said CVE-2026-72529 let an unauthenticated attacker use port 4307/TCP to trigger a hidden function and run a script on the server.

The second flaw, CVE-2026-72530, let an unauthenticated attacker use code injection to reach remote code execution, according to TrueConf. The company also said a code-generation problem could let someone who already had code execution leave its isolated environment and run commands on the host operating system.

CISA did not give attack details. Kaspersky said Head Mare had been exploiting both flaws since at least July 2026 to replace client installers with malicious versions that installed backdoor malware, and said the campaigns had hit Russian organisations in transport, energy, IT, electronics and software development.

In April 2026, Check Point Research said attackers were using CVE-2026-3502 in zero-day attacks it named Operation True Chaos and tied to Chinese threat actors. The article did not say whether that activity was connected to the two flaws CISA later added to its list.

Named in this story

Companies

TrueConf
its security team described the flaws
Kaspersky
said Head Mare had been exploiting the flaws since at least July 2026

Organisations

Head Mare
the hacktivist group Kaspersky linked to the exploitation
Check Point Research
reported attacks on another TrueConf flaw in April 2026

Governments and agencies

U.S. Cybersecurity and Infrastructure Security Agency
added the flaws to its KEV catalogue and set the patch deadline
U.S. Federal Civilian Executive Branch
the agencies ordered to secure affected servers

Products and systems

TrueConf Server
the self-hosted communications platform with the vulnerabilities
CVE-2026-72529
the missing-authentication flaw that allowed arbitrary script execution
CVE-2026-72530
the code-injection flaw that could lead to remote code execution
CVE-2026-3502
another TrueConf flaw targeted in zero-day attacks

How the source tells it

The register was a straightforward security report, with urgency and alarm supplied by deadlines, severity labels and warnings about federal risk.

  • urgency a two-week remediation deadline and an instruction to prioritise patching
  • alarm critical-severity labels and a warning about significant risks to the federal enterprise