Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

TrueConf flaws enabling attacks on meeting participants added to KEV catalog

Two critical vulnerabilities (CVE-2026-72529, CVSS 9.8, and CVE-2026-72530, CVSS 9.0) in TrueConf Server allow chained exploitation for remote server compromise and client-side malware distribution. The Head Mare APT group uses CVE-2026-72529 for initial access via TCP/4307, then CVE-2026-72530 to escalate to system-level code execution, ultimately replacing client software with PhantomCore malware. Affected versions are TrueConf Server below 5.3.9.10013/10015, 5.4.0.12689/12700 to below 5.4.9.10072/10019, and 5.5.0.13826 to below 5.5.5.10010; remediation requires upgrading to versions 5.3.9.10013/10015, 5.4.9.10072/10019, or 5.5.5.10010/10009 respectively.
Read Full Article →

Vulnerability Management , Patch/Configuration Management , Critical Infrastructure Security TrueConf flaws enabling attacks on meeting participants added to KEV catalog August 21, 2026 Share By Laura French (Credit: Postmodern Studio – stock.adobe.com) Two vulnerabilities in the TrueConf self-hosted video conferencing service that enable the compromise of TrueConf servers and attacks on meeting participants were added to the Known Exploited Vulnerabilities (KEV) catalog by the Cybersecurity and Infrastructure Security Agency (CISA) on Thursday. The vulnerabilities, tracked as CVE-2026-72529 and CVE-2026-72530 were exploited by the Head Mare APT hacktivist group, as reported by Kaspersky earlier this month. Attackers chained the flaws to compromise on-premises TrueConf instances and replace TrueConf client distribution files, spreading PhantomCore malware to meeting participants. TrueConf is used by hundreds and thousands of organizations globally, according to its website , and lists SpaceX and the Superior Court of California among its customers. It offers free and paid versions, and touts “military-grade” security with the ability to operate entirely on an organization’s own infrastructure. Kaspersky discovered that Head Mare attackers were using CVE-2026-72529 to gain initial access to TrueConf servers; the vulnerability enables remote, unauthorized access over the network via port 4307/TCP and execution of arbitrary scripts within an isolated environment by calling an undocumented function. With an initial foothold on the server, attackers then chained the second vulnerability, CVE-2026-72530, which enabled them to escape the isolated environment and execute arbitrary code on the server with system privileges. Head Mare leveraged this access to replace a TrueConf file, locale.php, with a web shell and install a backdoor, enabling further command execution with command-and-control (C2) communications going through attacker-controlled Microsoft OneDrive cloud storage. The attackers also replaced the TrueConf client distribution file, trueconf_windows_client_x64.exe, with a malicious version causing users who joined a TrueConf meeting on a compromised server to receive a prompt to install the trojanized version. The malicious installer delivered PhantomCore malware, which Kaspersky said “enables the attacker to execute arbitrary commands, essentially providing them with full control over the infected system.” Head Mare is a hacktivist group that targets Russian and Belarusian organizations; the group has been active since at least 2023 and has previously used LockBit and Babuk ransomware to encrypt victims’ systems, according to Kaspersky . The group has also previously exploited the WinRAR vulnerability tracked as CVE-2023-3881. To remediate CVE-2026-72529 and CVE-2026-72530, organizations should upgrade to TrueConf Server versions 5.3.9, 5.4.9 and 5.5.5. CISA requires federal civilian executive branch organizations to remediate by Aug. 23 for CVE-2026-72529 and Sept. 3 for CVE-2026-72530. Kaspersky noted that organizations that do not use their own TrueConf server could still be compromised if an employee has joined a TrueConf call hosted by another organization. Scanning for indicators of compromise and rotation of credentials for affected accounts are recommended in the case of a potential compromise. Laura French Related Vulnerability Management Critical vulnerability in Elementor Pro allows unauthenticated file upload and RCE SC Staff August 20, 2026 The vulnerability arises from a discrepancy between two loops within the File Upload module: one for validation and one for processing. Bug Bounties Vercel offers $1 million in bounties for sandbox hacks SC Staff August 20, 2026 The two-week program challenges participants to breach an isolated sandbox environment hosted by Vercel. Patch/Configuration Management Microsoft Defender bug causing crashes resolved SC Staff August 20, 2026 The bug caused Windows Defender quick or full scans to fail, sometimes requiring the service to be restarted. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article