News

CISA added two exploited TrueConf Server flaws to KEV, due August 23 and September 3 for federal agencies, but the Head Mare and PhantomCore attribution is Kaspersky's, not CISA's

CISA added CVE-2026-72529 (CVSS 9.8, unauthenticated) and CVE-2026-72530 (CVSS 9.0, sandbox escape) in self-hosted TrueConf Server to its Known Exploited Vulnerabilities catalog on August 20, with federal deadlines of August 23 and September 3. TrueConf fixed both in June (builds 5.3.9 / 5.4.9 / 5.5.5). CISA names no actor; Kaspersky ties the chain to Head Mare and the PhantomCore backdoor.

CISA added two exploited TrueConf Server flaws to KEV, due August 23 and September 3 for federal agencies, but the Head Mare and PhantomCore attribution is Kaspersky's, not CISA's

On August 20, CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog and set federal remediation deadlines under Binding Operational Directive 26-04. Read what CISA asserts and what it does not. The CISA alert and the KEV catalog say the two flaws are being exploited in the wild and put agencies on a clock, but they name no threat actor and no malware. The Head Mare group and the PhantomCore backdoor are Kaspersky's attribution, not CISA's. And the product is self-hosted TrueConf Server, the on-premises video conferencing server, not a cloud meeting service.

The instrument: an unauthenticated foothold chained to a sandbox escape

Two flaws in the same server, meant to be used together. Per TrueConf's advisory, CVE-2026-72529 (CVSS 9.8, missing authentication, CWE-306, tracked as KLCERT-26-057) is the way in: "A remote unauthenticated attacker connecting to TrueConf Server over 4307/TCP can invoke an undocumented critical function and execute an arbitrary script on the server." That port is the one TrueConf Server listens on by default. CVE-2026-72530 (CVSS 9.0, a sandbox escape and code injection, KLCERT-26-058 and BDU:2026-11247) is the follow-through: it breaks out of the sandbox so the attacker's script runs on the host rather than in a contained context. Chain them and an unauthenticated request on an exposed port becomes full control of the machine.

This is not a cloud zero-day and it is not a bug in a hosted meeting product. It is self-hosted TrueConf Server, and the "Russia's Zoom" framing some outlets reach for is color, not the instrument. The instrument is two CVEs on a box an administrator installed and exposed.

The number under the headline: two federal deadlines, and a fix that shipped in June

The wire version is "patch by September 3." The KEV catalog actually sets two different Federal Civilian Executive Branch deadlines: August 23 for CVE-2026-72529 and September 3 for CVE-2026-72530. The earlier date, for the unauthenticated flaw, is the one that bites first, and it is why this is a today problem rather than a next-week one. BleepingComputer collapsed both into a single September 3, and some write-ups list September 2 for the second flaw; the catalog says September 3.

The other number the headline skips is the fix date. TrueConf did not ship these patches this week. Its June 2026 update delivered the corrected builds, 5.3.9, 5.4.9 and 5.5.5, on June 18, and the vendor's guidance is blunt: "immediately upgrading to the latest versions." Every build below those in each branch is affected. So the patch has existed for two months, and the KEV listing marks exploitation catching up to an available fix, not a fresh drop with no remedy.

The attribution CISA did not make: Head Mare, PhantomCore, PhantomGraph

The actor and the malware are Kaspersky's finding, and Kaspersky is specific. In Securelist's account, "In July 2026, Kaspersky experts detected a new attack by the Head Mare group," a crew it now assesses as an APT rather than the hacktivists it once tracked. The operators "exploited a chain of vulnerabilities in the TrueConf video conferencing server and replaced the original TrueConf client installers with infected versions that installed the PhantomCore malware on the system," and Kaspersky names a second backdoor, PhantomGraph, in the same campaign. Kaspersky puts TrueConf Server builds going back to 2022 in scope.

CISA's alert carries none of those names. That gap is the one the "APT deploys PhantomCore" headlines paper over: exploitation and a federal deadline are CISA's claim, while the Head Mare attribution and the installer-swap tradecraft are Kaspersky's. TrueConf Server now sits on the same KEV catalog as CISA's earlier exploited-flaw batches, and the pattern is the same: a patched bug, exploited before defenders moved.

The takeaway

If you run internet-facing self-hosted TrueConf Server, treat it as already compromised until proven otherwise. Close or firewall 4307/TCP and move to 5.3.9, 5.4.9 or 5.5.5 now, because the fix has been out since June 18 and Head Mare has been chaining these since July. Federal agencies have until August 23 for the unauthenticated flaw and September 3 for the sandbox escape; everyone else should work to the earlier date, not the later one. And because the campaign swapped client installers, patching the server is not the whole job: check whether any TrueConf client was installed or updated from your server since July, because that is where PhantomCore rode in.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free