The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform, giving them until September 3 to secure their systems. The directive applies to U.S. Federal Civilian Executive Branch (FCEB) agencies and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on Thursday. CISA warned that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.

TrueConf Server is designed for secure corporate messaging and video conferencing, operating inside an organization's local network (LAN) rather than relying on cloud-based software such as Zoom or Microsoft Teams. The most severe of the two flaws, tracked as CVE-2026-72529, is a critical missing authentication issue that allows unprivileged attackers to remotely execute arbitrary scripts on unpatched servers. According to the TrueConf security team, a remote unauthenticated attacker connecting to the server over port 4307/TCP can invoke an undocumented critical function and execute an arbitrary script.

The second vulnerability, CVE-2026-72530, is also rated critical severity and can be exploited by unauthenticated threat actors through high-complexity code injection attacks to gain remote code execution. TrueConf explains that improper management of code generation could allow an attacker who has achieved code execution in the server's isolated environment to escape the sandbox and run arbitrary commands on the underlying operating system. Both flaws have been added to the KEV catalog due to active exploitation.

While CISA did not share specific details on the attacks, cybersecurity company Kaspersky attributed the exploitation of both CVE-2026-72529 and CVE-2026-72530 to the Head Mare hacktivist group. According to Kaspersky, Head Mare has been exploiting these vulnerabilities since at least July 2026 to replace client installers with malicious versions designed to deploy backdoor malware. Multiple Head Mare campaigns targeted Russian organizations across various industry sectors, including transportation, energy, IT, electronics, and software development.

This is not the first time TrueConf Server has been targeted. In April 2026, Check Point Research reported that hackers were exploiting another TrueConf flaw, tracked as CVE-2026-3502, in zero-day attacks dubbed "Operation True Chaos." Check Point linked those attacks to Chinese threat actors, who compromised users via trojanized client updates. The repeated targeting of TrueConf highlights the risks facing self-hosted platforms, which, while offering greater control over data, still require timely patching to remain secure.

CISA's order reflects the agency's broader push to address vulnerabilities that are known to be exploited in the wild, prioritizing federal network security. The two-week deadline for federal agencies underscores the urgency of applying the vendor's patches promptly. U.S. organizations using TrueConf Server beyond the federal government should also be aware of the active exploitation and take steps to protect their systems.

More cybersecurity news from TechManNews.