CVE Tools
Back to feed
Exploited in the wild TrueConf Server Head Mare rce TrueConf malware

CISA orders feds to patch actively exploited TrueConf Server flaws

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

CISA has directed U.S. federal agencies to remediate two critical vulnerabilities in TrueConf Server, which are currently under active exploitation in the wild. The first flaw, CVE-2026-72529, permits unauthenticated remote code execution via an undocumented function on port 4307/TCP, while CVE-2026-72530 enables a sandbox escape through complex code injection. Kaspersky identifies the hacktivist group Head Mare as the actor leveraging these weaknesses since July 2026 to distribute trojanized client installers containing backdoor malware, primarily targeting Russian organizations. Federal civilian executive branch agencies must complete patches by September 3.