Hackers are chaining two critical vulnerabilities in TrueConf, Russia’s alternative to Zoom, to compromise servers and infect online meeting participants with malware.
According to the US Cybersecurity and Infrastructure Security Agency (CISA), the vulnerabilities, tracked as CVE-2026-72529 and CVE-2026-72530, are already being exploited in active attacks. CISA said they are a “frequent attack vector” and pose a significant risk to federal information systems.
The first vulnerability allows an unauthenticated remote attacker to execute arbitrary scripts on a vulnerable TrueConf server by calling an undocumented function.
The second vulnerability allows an attacker to use a specially crafted script to escape the isolated environment and execute arbitrary code on the host system. This enables the attacker to replace one of the TrueConf Server files with their own web shell.
CISA has not specified who has been affected by these attacks. Kaspersky researchers discovered the vulnerabilities while investigating attacks against Russian organizations. The company linked the activity to Head Mare, a pro-Ukrainian hacktivist group also associated with the PhantomCore malware used in the attacks.
The threat is not limited to TrueConf server owners. Kaspersky researchers demonstrated a guest page for joining a conference that prompted users to download the application. The company warned that employees of other organizations who join meetings hosted on compromised TrueConf servers could also download the infected installer.
The vulnerabilities affect all TrueConf Server versions before 5.3, as well as versions 5.3.x before 5.3.9, 5.4.x before 5.4.9, and 5.5.x before 5.5.5. TrueConf addressed the flaws in versions 5.3.9, 5.4.9, and 5.5.5, released on June 18th.
Although TrueConf was developed by a Russian IT company, its solutions are reportedly used in more than 100 countries worldwide. These include a small number of companies in the US, Germany, and Italy.
US federal agencies must remediate the vulnerabilities by September 10th. CISA is also urging all organizations to apply patches for vulnerabilities added to its KEV catalog as soon as possible.