TWO critical vulnerabilities in TrueConf Server, CVE-2026-72529 and CVE-2026-72530, have been added to CISA's Known Exploited Vulnerabilities catalog. Both are being actively exploited in the wild, enabling attackers to execute code and install the PhantomCore malware. The flaws have a high severity score of 9.8 and 9.0 according to CVSSv3, with remote unauthorized access available via TCP port 4307 without authentication. Affected versions include TrueConf Server 5.3.x to 5.5.5 and earlier.
Patches have been released, and users are urged to update to the latest versions (5.3.9, 5.4.9, 5.5.5). The vulnerabilities pose significant risks not only to TrueConf users but can also be leveraged in supply chain attacks.