TrueConf Server actively exploited arbitrary code execution and sandbox escape flaws security flaw
Vulnerability
Summary
Hide ▲
Show ▼
TrueConf Server vulnerabilities KLCERT-26-057 and KLCERT-26-058 were exploited in July 2026 by Head Mare against unpatched Russian companies using exposed TCP port 4307. The chain let attackers run code as NT AUTHORITY\SYSTEM, replace \public\js\locale.php with a web shell, and swap the legitimate TrueConf Client installer for a poisoned build. That activity delivered PhantomCore and PhantomGraph; the latter used SysExcSvc.dll and SysReadSvc.dll with Microsoft OneDrive as C2, and Kaspersky said the vendor patched affected releases on June 18, 2026.
Related Happenings
CISA KEV patch directive for TrueConf Server flaws
Public Sector Action
H score37
First: 21.08.2026 15:25
Last: 21.08.2026 15:25
Sources 1
About this happening:
CISA added CVE-2026-72529 and CVE-2026-72530 to its KEV catalog and ordered FCEB agencies to secure TrueConf Server within two weeks, forcing rapid federal res...
CISA KEV patch directive for TrueConf Server flaws
Public Sector ActionAbout this happening: CISA added CVE-2026-72529 and CVE-2026-72530 to its KEV catalog and ordered FCEB agencies to secure TrueConf Server within two weeks, forcing rapid federal res...
PhantomCore TrueConf server targeting campaign in Russia
Campaign
H score34
First: 27.04.2026 14:54
Last: 27.04.2026 14:54
Sources 1
How related:
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors.
About this happening:
Head Mare is exploiting unpatched TrueConf Server flaws to replace TrueConf Client installer updates with trojanized builds that deliver PhantomCore and PhantomG...
PhantomCore TrueConf server targeting campaign in Russia
CampaignHow related: The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors.
About this happening: Head Mare is exploiting unpatched TrueConf Server flaws to replace TrueConf Client installer updates with trojanized builds that deliver PhantomCore and PhantomG...
Latest development: 08.08.2026 17:16
Head Mare is exploiting unpatched TrueConf Server flaws to replace legitimate TrueConf Client installers with trojanized updates that deliver PhantomCore and PhantomGraph backdoors, using a web shell for persistent access and targeting Russian organizations across instrumentation, electronics, transportation, energy, IT, and software development sectors.
TrueConf Server exploit chain (multiple vulnerabilities)
Vulnerability
H score56
First: 27.04.2026 14:54
Last: 27.04.2026 14:54
Sources 1
About this happening:
TrueConf Server is exposed by a three-flaw exploit chain that enabled unauthenticated admin access, arbitrary file read, and remote command execution on susceptibl...
TrueConf Server exploit chain (multiple vulnerabilities)
VulnerabilityAbout this happening: TrueConf Server is exposed by a three-flaw exploit chain that enabled unauthenticated admin access, arbitrary file read, and remote command execution on susceptibl...
TrueConf update integrity flaw actively exploited (CVE-2026-3502)
Vulnerability
H score69
First: 02.04.2026 00:35
Last: 02.04.2026 00:35
Sources 1
About this happening:
CVE-2026-3502 is an actively exploited TrueConf update-integrity flaw that lets attackers replace legitimate updates with malicious executables and trigger arbitrary fil...
TrueConf update integrity flaw actively exploited (CVE-2026-3502)
VulnerabilityAbout this happening: CVE-2026-3502 is an actively exploited TrueConf update-integrity flaw that lets attackers replace legitimate updates with malicious executables and trigger arbitrary fil...
TrueChaos TrueConf CVE-2026-3502 campaign targeting Southeast Asian government entities
Campaign
H score79
First: 02.04.2026 00:35
Last: 02.04.2026 00:35
Sources 1
About this happening:
The TrueChaos campaign has been exploiting CVE-2026-3502 in TrueConf zero-day attacks against government entities in Southeast Asia, turning compromised servers in...
TrueChaos TrueConf CVE-2026-3502 campaign targeting Southeast Asian government entities
CampaignAbout this happening: The TrueChaos campaign has been exploiting CVE-2026-3502 in TrueConf zero-day attacks against government entities in Southeast Asia, turning compromised servers in...
Timeline
-
08.08.2026 17:16 1 articles · 13d ago
TrueConf releases fixes for KLCERT-26-057 and KLCERT-26-058
Mitigation Patch UpdateTrueConf released versions 5.3.9, 5.4.9, and 5.5.5 on June 18 to fix KLCERT-26-057 and KLCERT-26-058, flaws affecting TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions; the weaknesses enabled malicious script execution inside the isolated TrueConf environment, sandbox escape, and operating-system command execution.
Show sources
- Hackers breach TrueConf to trojanize client installers with backdoors — www.bleepingcomputer.com — 08.08.2026 17:16
-
08.08.2026 17:16 3 articles · 13d ago
Head Mare abuses TrueConf Server to deploy PhantomCore and PhantomGraph
Technical Analysis UpdateKaspersky says Head Mare exploited unpatched TrueConf Server systems used by Russian organizations, connecting over TCP port 4307 without authentication, using KLCERT-26-057 and KLCERT-26-058 to run a malicious script, escape the sandbox, elevate to NT AUTHORITY\SYSTEM, replace \public\js\locale.php with a web shell, and swap the legitimate TrueConf Client installer for a trojanized build carrying PhantomCore; PhantomGraph, delivered as SysExcSvc.dll and SysReadSvc.dll, accepted commands through Microsoft OneDrive and was observed dumping LSASS memory and running reconnaissance commands. Kaspersky says it discovered the attack in July.
Show sources
- Hackers breach TrueConf to trojanize client installers with backdoors — www.bleepingcomputer.com — 08.08.2026 17:16
- Hackers breach TrueConf to trojanize client installers with backdoors — www.bleepingcomputer.com — 08.08.2026 17:16
- TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore — thehackernews.com — 10.08.2026 14:33