CISA Orders Urgent Patch for Exploited TrueConf Server Flaws

The Cybersecurity and Infrastructure Security Agency ordered US federal agencies to patch two critical unauthenticated remote code execution vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server by September 2026. The flaws are actively exploited by the Head Mare threat actor to deploy PhantomCore malware.

7 reportsother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communic

mastodon:infosec-exchangeother39d ago kagi ↗

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. https://www. bleepingcomputer.com/news/secu rity/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/

"CISA orders feds to patch actively exploited TrueConf Server flaws" "[...] federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communicat

mastodon:infosec-exchangeother39d ago kagi ↗

"CISA orders feds to patch actively exploited TrueConf Server flaws" "[...] federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. The U.S." https://www. bleepingcomputer.com/news/secu rity/cisa-orders-feds-to-patch-actively-exploited-trueconf-ser

🤖 CISA added two actively exploited TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to patch. TrueConf is a self-hosted communications

mastodon:infosec-exchangeother39d ago kagi ↗

🤖 CISA added two actively exploited TrueConf Server vulnerabilities to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to patch. TrueConf is a self-hosted communications platform; apply vendor updates promptly. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisa-orders-feds-to-patch-actively-exploited-trueconf-server-flaws/ # CyberSec # CVE # Exploit

⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively

mastodon:infosec-exchangeother38d ago kagi ↗

⚠️ CRITICAL: CISA orders feds to patch actively exploited TrueConf Server flaws Two critical unauthenticated RCE vulnerabilities (CVE-2026-72529, CVE-2026-72530) in TrueConf Server are being actively exploited by Head Mare group to deploy backdoor malware via trojanized installers. Any organization running TrueConf Server is at immediate risk of compromise. https:// threatnoir.com/focus # infosec

CISA orders federal agencies to patch two critical TrueConf Server flaws by September. Both actively exploited by Head Mare to deploy PhantomCore malware. Deadlines: https:// deafnews.it/en/article/ci

mastodon:infosec-exchangeother37d ago kagi ↗

CISA orders federal agencies to patch two critical TrueConf Server flaws by September. Both actively exploited by Head Mare to deploy PhantomCore malware. Deadlines: https:// deafnews.it/en/article/cisa-or ders-september-patches-two-critical-trueconf-flaws-actively-exploited