Back to advisories

CISA orders feds to patch actively exploited TrueConf Server flaws

Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise.

CRITICALAdvisoryAug 22, 2026
Action required
Identify and patch all TrueConf Server instances to the latest patched version immediately. Scan for trojanized TrueConf client installers on endpoints and hunt for suspicious outbound connections from affected servers.
Affected products
TrueConf ServerTrueConfZoomMicrosoft Teams