CISA Orders Emergency Patching for Critical TrueConf Server Vulnerabilities Under Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (**CISA**) has issued a critical directive for federal agencies, mandating immediate patching for two actively exploited vulnerabilities within the **TrueConf Server** self-hosted communications platform. These flaws, including a critical missing authentication vulnerability and a sandbox escape, pose significant risks, with reports indicating their exploitation by threat actors to deploy backdoor malware.
The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** has ordered all U.S. Federal Civilian Executive Branch (**FCEB**) agencies to prioritize patching two critical and actively exploited vulnerabilities in the **TrueConf Server** platform. **TrueConf Server** is a self-hosted solution for secure corporate messaging and video conferencing, operating within an organization's local network rather than a cloud environment.
### Critical Flaws Demand Immediate Attention
The more severe of the two is a critical missing authentication security flaw, tracked as **CVE-2026-72529**. This vulnerability allows unprivileged attackers to remotely execute arbitrary scripts on unpatched servers. The **TrueConf** security team elaborated, stating that "A remote unauthenticated attacker connecting to **TrueConf Server** over 4307/TCP can invoke an undocumented critical function and execute an arbitrary script on the server."
The second critical vulnerability, **CVE-2026-72530**, enables unauthenticated threat actors to achieve remote code execution through high-complexity code injection attacks. **TrueConf** further explained, "Improper management of code generation can allow an attacker who has achieved code execution in the **TrueConf Server** isolated environment to escape the sandbox and execute arbitrary commands on the underlying operating system."
### CISA Mandate and Active Exploitation
**CISA** added both flaws to its Known Exploited Vulnerabilities (**KEV**) catalog, setting a deadline of September 3 for federal agencies to secure their servers. The agency emphasized the severity, warning that "This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise."
While **CISA** did not disclose specific attack details, cybersecurity firm **Kaspersky** reported that the **Head Mare** hacktivist group has been exploiting **CVE-2026-72529** and **CVE-2026-72530** since at least July 2026. These exploits have been used to replace legitimate **TrueConf** client installers with malicious versions designed to deploy backdoor malware. **Kaspersky** noted that multiple **Head Mare** campaigns have targeted Russian organizations across various sectors, including transportation, energy, IT, electronics, and software development.
This isn't the first time **TrueConf** has been a target. In April 2026, **Check Point Research** reported on "Operation True Chaos," where hackers, linked to Chinese threat actors, exploited another **TrueConf** flaw (**CVE-2026-3502**) in zero-day attacks, compromising users via trojanized client updates.
