Exploited in the wild TrueConf Server Head Mare rce TrueConf malware
CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities
CVE Tools coverage
CISA has added two critical vulnerabilities affecting TrueConf Server, CVE-2026-72529 and CVE-2026-72530, to its Known Exploited Vulnerabilities catalog following reports of active use by the hacktivist group Head Mare. These flaws allow remote attackers with access to port 4307/TCP to execute arbitrary code on the host system, enabling the deployment of the PhantomCore malware. Federal agencies are urged to apply patches immediately, while all users of affected server versions should update to releases 5.3.9, 5.4.9, or 5.5.5 to mitigate the risk.