TrueConf Server actively exploited arbitrary code execution and sandbox escape flaws security flaw
Vulnerability
Summary
Hide ▲
Show ▼
TrueConf Server flaws KLCERT-26-057 and KLCERT-26-058 were used in active attacks to escape the sandbox and reach the underlying OS, exposing older servers to SYSTEM-level code execution. The weaknesses affect 5.3.x before 5.3.9, 5.4.x before 5.4.9, and 5.5.x before 5.5.5. The vendor fixed the issues on June 18.
Related Happenings
PhantomCore TrueConf server targeting campaign in Russia
Campaign
H score34
First: 27.04.2026 14:54
Last: 27.04.2026 14:54
Sources 1
How related:
Kaspersky reports that Head Mare uses a web shell to collect sensitive information from the victim’s environment, access the TrueConf database, and replace the legitimate TrueConf Client installer hosted on the server with a malicious version that contains the PhantomCore backdoor.
About this happening:
Head Mare is exploiting unpatched TrueConf Server flaws to replace TrueConf Client installer updates with trojanized builds that deliver PhantomCore and PhantomG...
PhantomCore TrueConf server targeting campaign in Russia
CampaignHow related: Kaspersky reports that Head Mare uses a web shell to collect sensitive information from the victim’s environment, access the TrueConf database, and replace the legitimate TrueConf Client installer hosted on the server with a malicious version that contains the PhantomCore backdoor.
About this happening: Head Mare is exploiting unpatched TrueConf Server flaws to replace TrueConf Client installer updates with trojanized builds that deliver PhantomCore and PhantomG...
Latest development: 08.08.2026 17:16
Head Mare is exploiting unpatched TrueConf Server flaws to replace legitimate TrueConf Client installers with trojanized updates that deliver PhantomCore and PhantomGraph backdoors, using a web shell for persistent access and targeting Russian organizations across instrumentation, electronics, transportation, energy, IT, and software development sectors.
TrueConf Server exploit chain (multiple vulnerabilities)
Vulnerability
H score56
First: 27.04.2026 14:54
Last: 27.04.2026 14:54
Sources 1
About this happening:
TrueConf Server is exposed by a three-flaw exploit chain that enabled unauthenticated admin access, arbitrary file read, and remote command execution on susceptibl...
TrueConf Server exploit chain (multiple vulnerabilities)
VulnerabilityAbout this happening: TrueConf Server is exposed by a three-flaw exploit chain that enabled unauthenticated admin access, arbitrary file read, and remote command execution on susceptibl...
Timeline
-
08.08.2026 17:16 1 articles · 3h ago
TrueConf releases fixes for KLCERT-26-057 and KLCERT-26-058
Mitigation Patch UpdateTrueConf released versions 5.3.9, 5.4.9, and 5.5.5 on June 18 to fix KLCERT-26-057 and KLCERT-26-058, flaws affecting TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions; the weaknesses enabled malicious script execution inside the isolated TrueConf environment, sandbox escape, and operating-system command execution.
Show sources
- Hackers breach TrueConf to trojanize client installers with backdoors — www.bleepingcomputer.com — 08.08.2026 17:16
-
08.08.2026 17:16 2 articles · 3h ago
Head Mare abuses TrueConf Server to deploy PhantomCore and PhantomGraph
Technical Analysis UpdateKaspersky says Head Mare exploited unpatched TrueConf Server systems used by Russian organizations, connecting over TCP port 4307 without authentication, using KLCERT-26-057 and KLCERT-26-058 to run a malicious script, escape the sandbox, elevate to NT AUTHORITY\SYSTEM, replace \public\js\locale.php with a web shell, and swap the legitimate TrueConf Client installer for a trojanized build carrying PhantomCore; PhantomGraph, delivered as SysExcSvc.dll and SysReadSvc.dll, accepted commands through Microsoft OneDrive and was observed dumping LSASS memory and running reconnaissance commands. Kaspersky says it discovered the attack in July.
Show sources
- Hackers breach TrueConf to trojanize client installers with backdoors — www.bleepingcomputer.com — 08.08.2026 17:16
- Hackers breach TrueConf to trojanize client installers with backdoors — www.bleepingcomputer.com — 08.08.2026 17:16