TechNewsReel
Live

CISA Warns of Active Exploitation of TrueConf Server Vulnerabilities

Federal agencies are urged to patch critical flaws being weaponized by pro-Ukrainian hacktivists to breach networks.

TechNewsReel Newsroom · August 21, 2026

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning after two critical vulnerabilities in TrueConf Server were found to be actively exploited in the wild. The agency added CVE-2026-72529 and CVE-2026-72530 to its Known Exploited Vulnerabilities (KEV) catalog on August 20, 2026, signaling an immediate risk to organizations using the platform.

According to CISA and security reports, the flaws are being leveraged by 'Head Mare,' a pro-Ukrainian hacktivist group. The attackers utilize these vulnerabilities to deploy the 'PhantomCore' backdoor, as well as 'PhantomGraph,' by trojanizing legitimate client installers to infiltrate target networks. To mitigate these risks, TrueConf released patches on June 18, 2026; the vulnerabilities were addressed in TrueConf Server versions 5.3.9, 5.4.9, and 5.5.5.

The Geopolitical Context

TrueConf is a Russian-developed enterprise video conferencing platform designed as a self-hosted alternative to services like Zoom. Because the software is deployed on an organization's own internal servers rather than a third-party cloud, it provides a direct entry point for attackers seeking to breach corporate or government perimeters.

This specific campaign is part of a broader pattern of geopolitical cyber-warfare. The PhantomCore operation has been targeting Russian entities since September 2025. However, because TrueConf is used globally, any organization running an unpatched version of the server is susceptible to these attacks, regardless of their geographic location or political affiliation.

Why It Matters

The inclusion of these bugs in the KEV catalog confirms that the vulnerabilities are no longer theoretical risks but are being weaponized for active intrusions. For administrators, the stakes are high: failure to update the software allows attackers to bypass authentication or execute remote code. In a worst-case scenario, this leads to a full system takeover, allowing threat actors to exfiltrate sensitive data or move laterally through a secure network.

What's Next

Organizations using TrueConf Server must verify their current version and apply the June 2026 updates immediately. Security teams should also audit their environments for signs of the PhantomCore backdoor, particularly focusing on the integrity of client installers. While the primary targets remain Russian-aligned, the persistence of the Head Mare group suggests that any exposed TrueConf instance remains a high-priority target for infiltration.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.