CISA added two exploited TrueConf Server flaws to KEV, due August 23 and September 3 for federal agencies, but the Head Mare and PhantomCore attribution is Kaspersky's, not CISA's
CISA added CVE-2026-72529 (CVSS 9.8, unauthenticated) and CVE-2026-72530 (CVSS 9.0, sandbox escape) in self-hosted TrueConf Server to its Known Exploited Vulnerabilities catalog on August 20, with federal deadlines of August 23 and September 3. TrueConf fixed both in June (builds 5.3.9 / 5.4.9 / 5.5.5). CISA names no actor; Kaspersky ties the chain to Head Mare and the PhantomCore backdoor.

On August 20, CISA added two TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog and set federal remediation deadlines under Binding Operational Directive 26-04. The CISA alert and the KEV catalog say the two flaws are being exploited in the wild and put agencies on a clock, but they name no threat actor and no malware. The Head Mare group and the PhantomCore backdoor are Kaspersky's attribution, not CISA's. The product is self-hosted TrueConf Server, the on-premises video conferencing server, not a cloud meeting service.
Per TrueConf's advisory, CVE-2026-72529 (CVSS 9.8, missing authentication, CWE-306, tracked as KLCERT-26-057) is the way in: "A remote unauthenticated attacker connecting to TrueConf Server over 4307/TCP can invoke an undocumented critical function and execute an arbitrary script on the server." That port is the one TrueConf Server listens on by default.
CVE-2026-72530 (CVSS 9.0, a sandbox escape and code injection, KLCERT-26-058 and BDU:2026-11247) is the follow-through. It breaks out of the sandbox so the attacker's script runs on the host rather than in a contained context. Chained together, an unauthenticated request on an exposed port becomes full control of the machine.
Some outlets reach for a "Russia's Zoom" label. The bugs sit on a box an administrator installed and exposed.
The KEV catalog sets two different Federal Civilian Executive Branch deadlines: August 23 for CVE-2026-72529 and September 3 for CVE-2026-72530. The earlier date, for the unauthenticated flaw, is the one that lands first. BleepingComputer collapsed both into a single September 3, and some write-ups list September 2 for the second flaw. The catalog says September 3.
TrueConf did not ship these patches the week of the KEV listing. Its June 2026 update delivered the corrected builds, 5.3.9, 5.4.9 and 5.5.5, on June 18, and the vendor's guidance is blunt: "immediately upgrading to the latest versions." Every build below those in each branch is affected. The patch has existed for two months. The KEV listing marks exploitation catching up to an available fix.
In Securelist's account, "In July 2026, Kaspersky experts detected a new attack by the Head Mare group," a crew it now assesses as an APT rather than the hacktivists it once tracked. The operators "exploited a chain of vulnerabilities in the TrueConf video conferencing server and replaced the original TrueConf client installers with infected versions that installed the PhantomCore malware on the system," and Kaspersky names a second backdoor, PhantomGraph, in the same campaign. Kaspersky puts TrueConf Server builds going back to 2022 in scope.
CISA's alert carries none of those names. Exploitation and a federal deadline are CISA's claim. The Head Mare attribution and the installer-swap tradecraft are Kaspersky's. TrueConf Server now sits on the same KEV catalog as CISA's earlier exploited-flaw batches, a patched bug exploited before defenders moved.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free