www.securityweek.com 8/21/2026, 7:50:41 AM · external

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
Developing story vulnerability 8 articles tracked
TrueConf Server authentication bypass and code injection flaws (CVE-2026-72529, CVE-2026-72530) exploited
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Status Unknown
Threat Actor

CISA has warned federal agencies about two critical vulnerabilities in TrueConf, a secure video conferencing platform. The vulnerabilities, CVE-2026-72529 and CVE-2026-72530, allow attackers to execute arbitrary code remotely. Exploitations can lead to attacks like the deployment of PhantomCore malware by the hacktivist group Head Mare, which has been using these vulnerabilities to compromise systems and gain access to sensitive information. Organizations using TrueConf are urged to update to patched versions and check for signs of intrusions.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline