logo

CISA orders feds to patch actively exploited TrueConf Server flaws

ID: dcf9248b-0ff8-536e-b66b-5fe24e53ae02

STIX ID: report--dcf9248b-0ff8-536e-b66b-5fe24e53ae02

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: Sergiu Gatlan

...
...

CISA has ordered U.S. federal agencies to urgently patch two critical unauthenticated remote code execution vulnerabilities in TrueConf Server (CVE-2026-72529 and CVE-2026-72530) after evidence of active exploitation; the flaws allow attackers to invoke undocumented functions, execute arbitrary scripts, and escape sandboxed environments. Kaspersky reports the Head Mare hacktivist group has been exploiting these issues since at least July 2026 to replace client installers with backdoors across multiple Russian industry sectors, and earlier activity (CVE-2026-3502) was linked to other threat actors via trojanized updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.