CISA Urges Immediate Patching of Critical TrueConf Server Vulnerabilities

CISA Urges Immediate Patching of Critical TrueConf Server Vulnerabilities

First seen 21 Aug 2026, 12:48 UTC Securityaffairs.CoBleepingcomputertrueconf.com 86% similarity 72.9

Article Content

Browse articles
ThreatCluster

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to prioritize patching two critical vulnerabilities in TrueConf Server, a self-hosted communications platform. These vulnerabilities, CVE-2026-72529 and CVE-2026-72530, allow unauthenticated attackers to execute arbitrary scripts and escape sandbox restrictions, respectively. Both flaws were published on August 19, 2026, and added to CISA's Known Exploited Vulnerabilities catalog on August 20, 2026. The vulnerabilities are actively exploited, with reports of the Head Mare hacktivist group targeting them since July 2026. Organizations using TrueConf Server are at risk, especially those in sectors like transportation and energy. CISA has mandated that federal agencies secure their systems by September 3, 2026. The situation highlights the urgency for organizations to update their systems to mitigate these risks.

Key Points: • CISA ordered federal agencies to patch two critical TrueConf Server vulnerabilities by September 3. • CVE-2026-72529 allows remote unauthenticated script execution on unpatched servers. • CVE-2026-72530 enables attackers to escape sandbox restrictions and execute commands on the OS.

ThreatCluster AI How this analysis works

Timeline

2026-03-30
CVE-2026-3502 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-19
CVE-2026-72529 and CVE-2026-72530 published
Two critical vulnerabilities in TrueConf Server were disclosed, allowing remote code execution.
BleepingComputer
2026-08-20
CVE-2026-72529 and CVE-2026-72530 added to CISA KEV
CISA added the vulnerabilities to its Known Exploited Vulnerabilities catalog due to active exploitation.
SecurityAffairs
2026-08-21
CISA mandates patching for federal agencies
CISA ordered federal agencies to secure their TrueConf Servers by September 3, 2026, due to critical vulnerabilities.
BleepingComputer

Community

Browse all →