ZeroHour
Product

TrueConf Server

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

Head Mare exploits TrueConf server flaws to install web shells and deliver PhantomCore and PhantomGraph backdoors at Russian organizations.

Kaspersky detected July 2026 attacks by the threat actor Head Mare exploiting a vulnerability chain (KLCERT-26-057 and KLCERT-26-058) in unpatched TrueConf videoconferencing servers. The chain enables arbitrary code execution with SYSTEM privileges, deployment of a web shell at locale.php, and replacement of client installers with versions delivering the PhantomCore backdoor and PhantomGraph, which uses Microsoft OneDrive as C2. Targets span Russian instrumentation, electronics, transport, energy, IT, and software firms. Patches shipped in TrueConf Server 5.3.9, 5.4.9, and 5.5.5 on June 18, 2026.

The Hacker News · 25d agoThreat actor in the wild1

U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog

CISA added two exploited TrueConf Server flaws (CVE-2026-72529, CVE-2026-72530) to its KEV catalog with federal patch deadlines.

CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-72529 (CVSS 9.3), a missing-authentication remote code execution flaw reachable on TCP port 4307, and CVE-2026-72530 (CVSS 9.5), a sandbox escape allowing code execution on the underlying host. Both flaws affect TrueConf Server versions 5.3.x through 5.5.5 and earlier, and were discovered by Vyacheslav Kopeytsev of Kaspersky ICS CERT. Under BOD 22-01, federal civilian agencies must patch CVE-2026-72529 by August 23, 2026, and CVE-2026-72530 by September 2, 2026.

Security Affairs · 25d agoExploit / PoC in the wildCVE-2026-72529CVE-2026-72530

Related CVEs

  • Code Injection Sandbox Escape in TrueConf Server Allows Host RCE via TCP 4307
    TrueConf Server contains a code injection flaw (CWE-94) that allows a remote, unauthenticated attacker with network access to TCP port 4307 to send a specially crafted script that breaks out of the server's isolated environment and executes arbitrary code on the underlying host. The flaw affects TrueConf Server 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier releases. A successful attack yields full code execution on the host system, not just the conferencing application, although the critical CVSS 4.0 score of 9.5 includes high attack complexity and attack-requirements factors. Organizations running self-hosted TrueConf video conferencing servers, especially those with port 4307 exposed to untrusted networks, are in scope. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-08-20, a public PoC exists, and Kaspersky's Securelist reports the Head Mare threat actor has actively targeted TrueConf Server to deploy PhantomCore malware.
    · TrueConf Server 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5, and earlier versions KEV PoC moderate
  • Unauthenticated RCE in TrueConf Server via undocumented function on port 4307
    CVE-2026-72529 is a missing-authentication vulnerability (CWE-306) in TrueConf Server that lets a remote, unauthenticated attacker reach an undocumented function over TCP port 4307 and execute an arbitrary script on the server. It is triggered simply by sending crafted requests to that port on an affected build, with no credentials or user interaction required. Successful exploitation yields code execution with high impact on the server's confidentiality, integrity, and availability (CVSS 4.0 base score 9.3). Any organization running TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, or earlier versions is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-20, and a public Kaspersky (Securelist) report documents the Head Mare threat actor targeting TrueConf Server with the PhantomCore backdoor, confirming in-the-wild exploitation; EPSS currently estimates a 1.6% chance of exploitation in the next 30 days.
    · TrueConf Server 5.3.x through 5.3.9, 5.4.x through 5.4.9, 5.5.x through 5.5.5, and all earlier versions KEV PoC moderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.