Find notable cyber news and cases, enriched with sources, timelines, and signals.

TrueConf Server actively exploited arbitrary code execution and sandbox escape flaws security flaw

Vulnerability
First reported
Last updated
Happening score
H score 42
2 unique sources, 2 articles

Summary

Hide ▲

TrueConf Server vulnerabilities KLCERT-26-057 and KLCERT-26-058 were exploited in July 2026 by Head Mare against unpatched Russian companies using exposed TCP port 4307. The chain let attackers run code as NT AUTHORITY\SYSTEM, replace \public\js\locale.php with a web shell, and swap the legitimate TrueConf Client installer for a poisoned build. That activity delivered PhantomCore and PhantomGraph; the latter used SysExcSvc.dll and SysReadSvc.dll with Microsoft OneDrive as C2, and Kaspersky said the vendor patched affected releases on June 18, 2026.

Related Happenings

CISA KEV patch directive for TrueConf Server flaws

Public Sector Action
H score37 First: 21.08.2026 15:25 Last: 21.08.2026 15:25 Sources 1

About this happening: CISA added CVE-2026-72529 and CVE-2026-72530 to its KEV catalog and ordered FCEB agencies to secure TrueConf Server within two weeks, forcing rapid federal res...

PhantomCore TrueConf server targeting campaign in Russia

Campaign
H score34 First: 27.04.2026 14:54 Last: 27.04.2026 14:54 Sources 1

How related: The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors.

About this happening: Head Mare is exploiting unpatched TrueConf Server flaws to replace TrueConf Client installer updates with trojanized builds that deliver PhantomCore and PhantomG...

Latest development: 08.08.2026 17:16

Head Mare is exploiting unpatched TrueConf Server flaws to replace legitimate TrueConf Client installers with trojanized updates that deliver PhantomCore and PhantomGraph backdoors, using a web shell for persistent access and targeting Russian organizations across instrumentation, electronics, transportation, energy, IT, and software development sectors.

TrueConf Server exploit chain (multiple vulnerabilities)

Vulnerability
H score56 First: 27.04.2026 14:54 Last: 27.04.2026 14:54 Sources 1

About this happening: TrueConf Server is exposed by a three-flaw exploit chain that enabled unauthenticated admin access, arbitrary file read, and remote command execution on susceptibl...

TrueConf update integrity flaw actively exploited (CVE-2026-3502)

Vulnerability
H score69 First: 02.04.2026 00:35 Last: 02.04.2026 00:35 Sources 1

About this happening: CVE-2026-3502 is an actively exploited TrueConf update-integrity flaw that lets attackers replace legitimate updates with malicious executables and trigger arbitrary fil...

TrueChaos TrueConf CVE-2026-3502 campaign targeting Southeast Asian government entities

Campaign
H score79 First: 02.04.2026 00:35 Last: 02.04.2026 00:35 Sources 1

About this happening: The TrueChaos campaign has been exploiting CVE-2026-3502 in TrueConf zero-day attacks against government entities in Southeast Asia, turning compromised servers in...

Timeline

  1. 08.08.2026 17:16 1 articles · 13d ago

    TrueConf releases fixes for KLCERT-26-057 and KLCERT-26-058

    Mitigation Patch Update

    TrueConf released versions 5.3.9, 5.4.9, and 5.5.5 on June 18 to fix KLCERT-26-057 and KLCERT-26-058, flaws affecting TrueConf Server 5.3.x before 5.3.9, 5.4.x before 5.4.9, 5.5.x before 5.5.5, and older versions; the weaknesses enabled malicious script execution inside the isolated TrueConf environment, sandbox escape, and operating-system command execution.

    Show sources
  2. 08.08.2026 17:16 3 articles · 13d ago

    Head Mare abuses TrueConf Server to deploy PhantomCore and PhantomGraph

    Technical Analysis Update

    Kaspersky says Head Mare exploited unpatched TrueConf Server systems used by Russian organizations, connecting over TCP port 4307 without authentication, using KLCERT-26-057 and KLCERT-26-058 to run a malicious script, escape the sandbox, elevate to NT AUTHORITY\SYSTEM, replace \public\js\locale.php with a web shell, and swap the legitimate TrueConf Client installer for a trojanized build carrying PhantomCore; PhantomGraph, delivered as SysExcSvc.dll and SysReadSvc.dll, accepted commands through Microsoft OneDrive and was observed dumping LSASS memory and running reconnaissance commands. Kaspersky says it discovered the attack in July.

    Show sources