ZeroHour
Organization

Kaspersky ICS CERT

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog

CISA added two exploited TrueConf Server flaws (CVE-2026-72529, CVE-2026-72530) to its KEV catalog with federal patch deadlines.

CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-72529 (CVSS 9.3), a missing-authentication remote code execution flaw reachable on TCP port 4307, and CVE-2026-72530 (CVSS 9.5), a sandbox escape allowing code execution on the underlying host. Both flaws affect TrueConf Server versions 5.3.x through 5.5.5 and earlier, and were discovered by Vyacheslav Kopeytsev of Kaspersky ICS CERT. Under BOD 22-01, federal civilian agencies must patch CVE-2026-72529 by August 23, 2026, and CVE-2026-72530 by September 2, 2026.

Security Affairs · 25d agoExploit / PoC in the wildCVE-2026-72529CVE-2026-72530

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Unisoc modem firmware flaw CWE-1189 allows VoLTE video call RCE chain to gain full Android kernel access on T606/T612/T7250 chipsets; no patch yet.

SSD Secure Disclosure published the second stage of an exploit chain, first disclosed in March 2026, that achieves full Android kernel access on Unisoc modem firmware via a VoLTE video call. The privilege-escalation flaw, classified as CWE-1189 (Improper Isolation of Shared Resources on System-on-a-Chip), exploits shared physical memory between modem and application processor with no hardware boundary, letting modem code map the entire 32-bit address space and modify Android kernel pages via ARM Memory Protection Unit registers. Confirmed affected chipsets include Unisoc T606 (Motorola E13), T612 (Realme C33), and T7250 (Xiaomi Redmi A5), sold across more than 140 countries. No CVE has been assigned, the August 2026 Android Security Bulletin does not address it, and Unisoc has not responded to researchers; exploitation requires an attacker-controlled private 4G network and a victim answering the call.

Related CVEs

  • Code Injection Sandbox Escape in TrueConf Server Allows Host RCE via TCP 4307
    TrueConf Server contains a code injection flaw (CWE-94) that allows a remote, unauthenticated attacker with network access to TCP port 4307 to send a specially crafted script that breaks out of the server's isolated environment and executes arbitrary code on the underlying host. The flaw affects TrueConf Server 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier releases. A successful attack yields full code execution on the host system, not just the conferencing application, although the critical CVSS 4.0 score of 9.5 includes high attack complexity and attack-requirements factors. Organizations running self-hosted TrueConf video conferencing servers, especially those with port 4307 exposed to untrusted networks, are in scope. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-20, a public PoC exists, and Kaspersky's Securelist reports the Head Mare threat actor has actively targeted TrueConf Server to deploy PhantomCore malware.
    · TrueConf Server 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier versions KEV PoC moderate
  • Unauthenticated RCE in TrueConf Server via undocumented function on port 4307
    CVE-2026-72529 is a missing-authentication vulnerability (CWE-306) in TrueConf Server that lets a remote, unauthenticated attacker reach an undocumented function over TCP port 4307 and execute an arbitrary script on the server. It is triggered simply by sending crafted requests to that port on an affected build, with no credentials or user interaction required. Successful exploitation yields code execution with high impact on the server's confidentiality, integrity, and availability (CVSS 4.0 base score 9.3). Any organization running TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, or earlier versions is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-20, and a public Kaspersky (Securelist) report documents the Head Mare threat actor targeting TrueConf Server with the PhantomCore backdoor, confirming in-the-wild exploitation; EPSS currently estimates a 1.6% chance of exploitation in the next 30 days.
    · TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and all earlier versions KEV PoC moderate
  • The UE and the EMM communicate with each other using NAS messages.
    The UE and the EMM communicate with each other using NAS messages. When a new NAS message arrives from the EMM, the modem parses it and fills in internal objects based on the received data. A bug in the parsing code could be used by an attacker to remotely crash the modem, which could lead to DoS or RCE.Product: AndroidVersions: Android SoCAndroid ID: A-228868888
    · google android
  • In modem, there is a possible system crash due to improper input validation.
    In modem, there is a possible system crash due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed.

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.