Head Mare Weaponized TrueConf's Own Video-Call Client to Backdoor Its Users — CISA Added Both Bugs to KEV a Week After Disclosure
Two unauthenticated flaws let an APT group turn a video conferencing server into a malware-signing machine — trojanizing the official client installer that gets pushed to everyone who joins a call. EPSS still rates both bugs under 1%.

On August 19-20, 2026, CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog. TrueConf is a video-conferencing platform widely deployed across Russian industry and government. Kaspersky's ICS CERT had disclosed the flaws twelve days earlier, alongside a report that a group it now classifies as an APT — Head Mare — had already been chaining them since July to do something more interesting than a typical breach: replace the legitimate TrueConf client installer with a backdoored one, so that everyone who joined a call through a compromised server downloaded malware along with the app.
Neither bug has a public exploit. Neither scores above 1% on EPSS. Both were patched in June, seven weeks before this story broke. None of that stopped a nation-state-adjacent actor from using them as a foothold to poison a communications tool at the source.
Scores as of 2026-08-21live record →
Two bugs, one unauthenticated path to root
Both flaws sit on TrueConf Server's port 4307/TCP, which is open by default. Kaspersky's advisories (KLCERT-26-057 and KLCERT-26-058, mapped to CVE-2026-72529 and CVE-2026-72530) describe a two-stage chain, credited to Kaspersky Principal Security Researcher Vyacheslav Kopeytsev:
- CVE-2026-72529 (CWE-306, Missing Authentication for Critical Function) — an unauthenticated attacker calls an undocumented function over port 4307 to run an arbitrary script. NVD scores it CVSS 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- CVE-2026-72530 (CWE-94, Code Injection) — that script initially runs inside an isolated sandbox. A second, specially crafted script breaks out of the sandbox and executes arbitrary code on the host OS with NT AUTHORITY\SYSTEM. NVD scores it CVSS 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) — the AC:H reflects that Kaspersky's own advisory notes the escape 'may take several attempts.'
From sandbox escape to trojanized installer
Head Mare's TrueConf attack chain
- Unauthenticated connection to port 4307/TCP
- CVE-2026-72529: call undocumented function, run script
- Script executes inside isolated sandbox
- CVE-2026-72530: sandbox escape
- Code execution as NT AUTHORITY\SYSTEM
- Web shell replaces public/js/locale.php
- Recon + privileged access to TrueConf database
- Official client installer swapped for trojanized build
- Call participants download PhantomCore backdoor
- PhantomGraph backdoor deployed, C2 over OneDrive
Who Head Mare is, and why this isn't their first TrueConf campaign
Kaspersky had previously tracked Head Mare as a hacktivist crew. It has now reclassified the group as an APT, citing 'the sophistication of their TTPs and the absence of destructive activity (encryption, wiping) in the targeted infrastructures.' Current campaigns target Russian organizations across instrument manufacturing, electronics, transportation, energy, IT and software development, using phishing, exploitation of public-facing servers, and subcontractor compromise as entry points.
TrueConf specifically has been a repeat target. Positive Technologies disclosed a separate set of three TrueConf vulnerabilities (tracked under Russia's BDU identifiers, not the CVEs in this piece) in April 2026, reporting that Head Mare had been exploiting them since September 2025 to drop PHP web shells. This latest chain — CVE-2026-72529 and CVE-2026-72530 — is a second, distinct set of bugs in the same product, used for a more ambitious payload: not just a foothold, but a supply-chain-style trojanization of the software TrueConf's own users trust.
TrueConf / Head Mare timeline
- Earlier Head Mare campaign beginsA separate set of TrueConf zero-days (BDU-2025-10114/10115/10116) exploited to deliver PHP web shells, per Positive Technologies.
- Positive Technologies discloses the earlier flawsReports the Sept 2025 campaign and the BDU-tracked vulnerabilities publicly.
- TrueConf patches CVE-2026-72529 / CVE-2026-72530Fixed in versions 5.3.9, 5.4.9 and 5.5.5.
- Kaspersky detects renewed Head Mare activityThe now-patched flaws exploited against unpatched TrueConf servers to deploy PhantomCore and PhantomGraph.
- Kaspersky ICS CERT + Securelist publishAdvisories for both CVEs plus the full Head Mare technical report go live.
- CISA adds both CVEs to KEVFederal deadline follows under BOD 22-01.
| CVE-2026-72529 | CVE-2026-72530 | |
|---|---|---|
| CWE | CWE-306 — Missing Authentication for Critical Function | CWE-94 — Code Injection |
| Role in chain | Initial unauthenticated script execution | Sandbox escape to host-level code execution |
| CVSS (NVD) | 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) | 9.0 (AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H) |
| EPSS | 0.28% (21st pct.) | 0.34% (27th pct.) |
| Public exploit code | None found | None found |
| ATT&CK | T1190 Exploit Public-Facing Application | T1059 Command and Scripting Interpreter |
What's independently checkable vs. what rests on Kaspersky's telemetry
- CVE-2026-72529 and CVE-2026-72530 exist, with the CWE, CVSS vectors and affected-version ranges above (NVD).
- Both were added to CISA's KEV catalog on Aug 19-20, 2026.
- TrueConf shipped fixes in 5.3.9 / 5.4.9 / 5.5.5 on June 18, 2026.
- No public exploit code is indexed anywhere we checked (Metasploit, Nuclei, ExploitDB, GitHub).
- Attribution of the exploitation to 'Head Mare' specifically, and its reclassification from hacktivist to APT.
- The PhantomCore / PhantomGraph malware analysis, IOCs, and the OneDrive-as-C2 detail.
- The named target sectors (instrumentation, electronics, transport, energy, IT, software development) — no individual victims are named by Kaspersky either.
- The tie to the earlier Sept 2025 / April 2026 Positive Technologies campaign as the 'same actor, second attempt.'
What to actually do
- Patch TrueConf Server to 5.3.9, 5.4.9 or 5.5.5 (or later) — this closes both CVEs.
- Do not expose port 4307/TCP to the internet; restrict it to trusted management networks if it must exist at all.
- If you run an unpatched or recently-patched server, run a full AV scan and check for the indicators of compromise in Kaspersky's report (web shell hash, trojanized installer hash, C2 IPs/domains) before trusting it's clean.
- If your organization received TrueConf client installers from a third-party server (a partner's or vendor's instance) between July and August 2026, verify the installer's signature/hash against TrueConf's official release rather than assuming it's legitimate.
- Federal agencies: both CVEs are KEV-listed under BOD 22-01 — check your internal remediation deadline.
Vulnerability data current as of 2026-08-21live record →