Skip to content

CVE-2026-72529

CVE

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
August 21, 2026
Last Seen
August 21, 2026
API
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

The Head Mare hacktivist group has breached TrueConf video conferencing servers, exploiting vulnerabilities to replace legitimate client installers with malicious versions containing backdoors. The attackers executed arbitrary code with high privileges using two vulnerabilities tracked as KLCERT-26-...

Two critical vulnerabilities, CVE-2026-72530 and CVE-2026-72529, have been identified in TrueConf server versions 5.3.X to 5.5.5, allowing remote unauthorized attackers to exploit the server via TCP port 4307. CVE-2026-72530 enables attackers to execute arbitrary code by breaking out of an isolated...

Public Exploits

Checking GitHub for proof-of-concept code…