CISA Orders Federal Agencies to Patch Actively Exploited TrueConf Server Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two actively exploited vulnerabilities in the self-hosted TrueConf Server communications platform to its Known Exploited Vulnerabilities (KEV) catalog.
TrueConf Server provides secure corporate messaging and video conferencing. Unlike cloud-based services such as Zoom and Microsoft Teams, the platform is deployed on an organization’s local network (LAN), where it can be managed and hosted internally.
The most serious issue is a critical missing-authentication vulnerability, tracked as CVE-2026-72529. The flaw allows an unauthenticated, remote attacker to execute arbitrary scripts on an unpatched TrueConf Server.
“A remote, unauthenticated attacker who connects to a TrueConf server via 4307/TCP could call undocumented critical functionality and execute arbitrary script on the server,” the TrueConf security team explained.
The second vulnerability, CVE-2026-72530, is also exploitable without authentication. It could allow remote code execution through a complex code-injection attack.
“Poorly managed code generation could allow an attacker who executes code in the isolated environment of the TrueConf server to escape the sandbox and execute arbitrary commands on the underlying operating system,” TrueConf said.
On Thursday, CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog. The agency ordered U.S. Federal Civilian Executive Branch (FCEB) agencies to secure affected TrueConf Server installations by September 3, 2026.
“These types of vulnerabilities are a frequent attack vector for malicious cyber attackers and pose significant risks to federal enterprises,” CISA warned.
CISA did not disclose details about the attacks exploiting the TrueConf Server flaws. However, cybersecurity firm Kaspersky reported that the Hedmare hacktivist group has exploited CVE-2026-72529 and CVE-2026-72530 since at least July 2026.
According to Kaspersky, the attackers replaced legitimate TrueConf client installers with malicious versions designed to deliver backdoor malware. The campaigns targeted Russian organizations in several sectors, including transportation, energy, information technology, electronics, and software development.
TrueConf has faced other attacks recently. In April 2026, Check Point Research reported that threat actors were exploiting another TrueConf vulnerability, CVE-2026-3502, in a zero-day campaign dubbed “Operation True Chaos.” The campaign was linked to Chinese threat actors and put users at risk through a trojanized client update.
Organizations using TrueConf Server should review the vendor’s security advisories, apply the available security updates immediately, and investigate systems for signs of unauthorized access or malicious client installers.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




