Find notable cyber news and cases, enriched with sources, timelines, and signals.

TrueConf Server actively exploited arbitrary code execution and sandbox escape flaws security flaw

Vulnerability
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

TrueConf Server flaws KLCERT-26-057 and KLCERT-26-058 were used in active attacks to escape the sandbox and reach the underlying OS, exposing older servers to SYSTEM-level code execution. The weaknesses affect 5.3.x before 5.3.9, 5.4.x before 5.4.9, and 5.5.x before 5.5.5. The vendor fixed the issues on June 18.

Related Happenings

PhantomCore TrueConf server targeting campaign in Russia

Campaign
H score34 First: 27.04.2026 14:54 Last: 27.04.2026 14:54 Sources 1

How related: Kaspersky reports that Head Mare uses a web shell to collect sensitive information from the victim’s environment, access the TrueConf database, and replace the legitimate TrueConf Client installer hosted on the server with a malicious version that contains the PhantomCore backdoor.

About this happening: Head Mare is exploiting unpatched TrueConf Server flaws to replace TrueConf Client installer updates with trojanized builds that deliver PhantomCore and PhantomG...

Latest development: 08.08.2026 17:16

Head Mare is exploiting unpatched TrueConf Server flaws to replace legitimate TrueConf Client installers with trojanized updates that deliver PhantomCore and PhantomGraph backdoors, using a web shell for persistent access and targeting Russian organizations across instrumentation, electronics, transportation, energy, IT, and software development sectors.

TrueConf Server exploit chain (multiple vulnerabilities)

Vulnerability
H score56 First: 27.04.2026 14:54 Last: 27.04.2026 14:54 Sources 1

About this happening: TrueConf Server is exposed by a three-flaw exploit chain that enabled unauthenticated admin access, arbitrary file read, and remote command execution on susceptibl...

Timeline

  1. 08.08.2026 17:16 1 articles · 3h ago

    TrueConf releases fixes for KLCERT-26-057 and KLCERT-26-058

    Mitigation Patch Update

    TrueConf released versions 5.3.9, 5.4.9, and 5.5.5 on June 18 to fix KLCERT-26-057 and KLCERT-26-058, flaws affecting TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions; the weaknesses enabled malicious script execution inside the isolated TrueConf environment, sandbox escape, and operating-system command execution.

    Show sources
  2. 08.08.2026 17:16 2 articles · 3h ago

    Head Mare abuses TrueConf Server to deploy PhantomCore and PhantomGraph

    Technical Analysis Update

    Kaspersky says Head Mare exploited unpatched TrueConf Server systems used by Russian organizations, connecting over TCP port 4307 without authentication, using KLCERT-26-057 and KLCERT-26-058 to run a malicious script, escape the sandbox, elevate to NT AUTHORITY\SYSTEM, replace \public\js\locale.php with a web shell, and swap the legitimate TrueConf Client installer for a trojanized build carrying PhantomCore; PhantomGraph, delivered as SysExcSvc.dll and SysReadSvc.dll, accepted commands through Microsoft OneDrive and was observed dumping LSASS memory and running reconnaissance commands. Kaspersky says it discovered the attack in July.

    Show sources