CISA on Thursday added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities catalog.
CISA's order and the immediate compliance window
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to patch two exploited flaws in TrueConf, a Moscow-based video conferencing platform. Federal agencies have until September 10 to remediate the vulnerabilities CISA flagged.
CISA's update to the Known Exploited Vulnerabilities (KEV) catalog notes both CVE-2026-72529 and CVE-2026-72530 "have been used in real-world attacks," but the bulletin does not identify victims or locations tied to those exploitations.
How the two bugs combine to seize a server, according to Kaspersky
Security researchers at Kaspersky have publicly documented an exploitation chain that uses the two flaws together to achieve full control of a TrueConf Server. Kaspersky reports an unauthenticated attacker with network access to TCP port 4307 — a port TrueConf documentation says is open by default — can exploit the first flaw to run a malicious script.
The second flaw, Kaspersky says, allows that script to escape its isolated execution environment and execute arbitrary code on the underlying server. With that access, the researchers report, attackers planted a web shell, moved through victim infrastructure, and gained privileged access to the TrueConf database.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildFrom server takeover to trojanized clients: PhantomCore in the wild
Kaspersky reports the intruders replaced the legitimate TrueConf Windows client installer hosted on compromised servers with a trojanized installer carrying a backdoor identified as PhantomCore. That change can turn a hijacked conferencing server into a distribution point for malware.
The Kaspersky researcher warned this creates risk not only for organizations that operate vulnerable TrueConf Servers, but also for people who join conferences hosted on those compromised systems: attendees could download and run a compromised client provided by a third party's infrastructure.
TrueConf's footprint and the scope of exposure
TrueConf markets an on-premises alternative to cloud conferencing services, allowing organizations to run TrueConf Server on their own infrastructure — including in private networks — to control where calls and associated data reside. While the company's roots and much of its customer base are Russian, TrueConf says it has users worldwide and lists customers including Switzerland’s Department of Justice and Home Affairs, Istanbul Airport, and a news organization (which the reporting outlet has contacted to confirm).
According to the researcher, the flaws affect TrueConf Server releases going back to 2022. TrueConf shipped fixes on June 18 in versions 5.3.9, 5.4.9 and 5.5.5, and warned customers that skipping the update "could leave their conferencing systems exposed to attacks over the public internet." That said, exploitation requires network access to the vulnerable service; a server confined to an internal network would not be directly reachable from the internet unless an attacker had another route in.
Attribution reported by Kaspersky — Head Mare and targeted sectors
The only publicly documented exploit of these two CVEs so far comes from Kaspersky, which links them to Head Mare, a pro‑Ukrainian hacktivist group. Kaspersky says Head Mare's latest campaign targeted Russian companies across multiple industries, including transport, energy, electronics, information‑technology and software development.
CISA has not said whether it added the flaws to KEV because of the Kaspersky-documented attacks or because of evidence of exploitation elsewhere, including potentially against organizations in the United States.
What this means for federal agencies, TrueConf administrators, and meeting participants
- Federal agencies: CISA's KEV addition establishes a firm remediation deadline — agencies must patch by September 10. The immediate priority is installing TrueConf's June 18 fixes (versions 5.3.9, 5.4.9 and 5.5.5) or equivalent mitigations.
- TrueConf administrators and suppliers: Operators of on‑premises TrueConf Server should verify whether TCP port 4307 is exposed and apply the vendor updates; otherwise a compromised server can be used to host and distribute trojanized installers.
- Meeting participants and IT buyers: Organizations that routinely join conferences hosted by third parties should be aware of a supply‑chain risk — a compromised host can offer a trojanized client to attendees. Attendees and procurement teams should factor the source of installers into their trust decisions.
CISA's catalog entry and Kaspersky's technical findings together outline a straightforward but potent exploitation path: a default-open service, two chaining flaws, and the ability to turn a conferencing server into a malware distribution point. The remaining open question in the public record is whether the KEV listing responds only to the Kaspersky-documented Head Mare activity or to additional, unreported exploitations — a detail that will shape who is at risk beyond the known cases.




