Vulnerability Management, Patch/Configuration Management, Critical Infrastructure Security

TrueConf flaws enabling attacks on meeting participants added to KEV catalog

(Credit: Postmodern Studio – stock.adobe.com)

Two vulnerabilities in the TrueConf self-hosted video conferencing service that enable the compromise of TrueConf servers and attacks on meeting participants were added to the Known Exploited Vulnerabilities (KEV) catalog by the Cybersecurity and Infrastructure Security Agency (CISA) on Thursday.

The vulnerabilities, tracked as CVE-2026-72529 and CVE-2026-72530 were exploited by the Head Mare APT hacktivist group, as reported by Kaspersky earlier this month. Attackers chained the flaws to compromise on-premises TrueConf instances and replace TrueConf client distribution files, spreading PhantomCore malware to meeting participants.

TrueConf is used by hundreds and thousands of organizations globally, according to its website, and lists SpaceX and the Superior Court of California among its customers. It offers free and paid versions, and touts “military-grade” security with the ability to operate entirely on an organization’s own infrastructure.

Kaspersky discovered that Head Mare attackers were using CVE-2026-72529 to gain initial access to TrueConf servers; the vulnerability enables remote, unauthorized access over the network via port 4307/TCP and execution of arbitrary scripts within an isolated environment by calling an undocumented function.  

With an initial foothold on the server, attackers then chained the second vulnerability, CVE-2026-72530, which enabled them to escape the isolated environment and execute arbitrary code on the server with system privileges.

Head Mare leveraged this access to replace a TrueConf file, locale.php, with a web shell and install a backdoor, enabling further command execution with command-and-control (C2) communications going through attacker-controlled Microsoft OneDrive cloud storage.

The attackers also replaced the TrueConf client distribution file, trueconf_windows_client_x64.exe, with a malicious version causing users who joined a TrueConf meeting on a compromised server to receive a prompt to install the trojanized version.

The malicious installer delivered PhantomCore malware, which Kaspersky said “enables the attacker to execute arbitrary commands, essentially providing them with full control over the infected system.”

Head Mare is a hacktivist group that targets Russian and Belarusian organizations; the group has been active since at least 2023 and has previously used LockBit and Babuk ransomware to encrypt victims’ systems, according to Kaspersky. The group has also previously exploited the WinRAR vulnerability tracked as CVE-2023-3881.

To remediate CVE-2026-72529 and CVE-2026-72530, organizations should upgrade to TrueConf Server versions 5.3.9, 5.4.9 and 5.5.5. CISA requires federal civilian executive branch organizations to remediate by Aug. 23 for CVE-2026-72529 and Sept. 3 for CVE-2026-72530.

Kaspersky noted that organizations that do not use their own TrueConf server could still be compromised if an employee has joined a TrueConf call hosted by another organization. Scanning for indicators of compromise and rotation of credentials for affected accounts are recommended in the case of a potential compromise.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds