< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

CISA orders patching of exploited TrueConf vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has directed U.S. federal agencies to patch two actively exploited vulnerabilities in TrueConf Server video conferencing software. The flaws, identified as CVE-2026-72529 and CVE-2026-72530, allow remote unauthorized attackers to execute arbitrary scripts and escape isolated environments to gain control of the underlying host system.

Reports from Kaspersky indicate that the Ukrainian hacktivist group ‘Head Mare’ has been using these vulnerabilities to deploy malware against Russian and Belarusian targets, specifically hitting sectors such as energy, transport, and IT. While TrueConf is a Moscow-based company, it maintains a global user base, including organizations in Switzerland and Turkey.

Federal agencies have been given deadlines of August 23rd to patch the initial authentication vulnerability and September 3rd to address the environment escape flaw.

Entities

CISA · Head Mare · Kaspersky · TrueConf