Using Russia’s Zoom alternative TrueConf? Patch it now, CISA warns
The vulnerabilities can compromise both TrueConf servers and the devices of meeting participants.

Thomas Fuller/SOPA Images/LightRocket via Getty Images
- Hackers are exploiting two critical TrueConf flaws to compromise servers and spread malware to meeting participants.
- CISA says the vulnerabilities are a frequent attack vector and pose significant risks to federal systems.
- Kaspersky linked attacks on Russian organizations to Head Mare, a pro-Ukrainian hacktivist group using PhantomCore malware.
- TrueConf has patched affected versions, and federal agencies must apply fixes by September 10th.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Hackers are chaining two critical-severity vulnerabilities in Russia's Zoom alternative, TrueConf, to compromise servers and infect meeting participants with malware.
The vulnerabilities, tracked as CVE-2026-72529 and CVE-2026-72530, have been exploited in active attacks and are considered “a frequent attack vector” that poses significant risks to federal systems, according to the US Cybersecurity and Infrastructure Security Agency (CISA).
The first flaw allows an unauthenticated remote attacker to execute arbitrary scripts on a vulnerable TrueConf server by calling an undocumented function.
The second flaw lets them use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system. This enables the attacker to replace one of the TrueConf server files with their own web shell.
Although CISA doesn’t specify who is being impacted, Kaspersky discovered the vulnerabilities while investigating attacks against Russian organizations. The cybersecurity company linked them to Head Mare, a pro-Ukrainian hacktivist group associated with the PhantomCore malware deployed in the attacks.
In addition, the threat isn’t limited to TrueConf server owners. Kaspersky showed a guest page for joining a conference with a prompt to download the application and warned that employees of other organizations who join meetings hosted on compromised TrueConf servers could also download the infected installer.
The flaws affect all TrueConf Server versions before 5.3, as well as versions 5.3.x before 5.3.9, 5.4.x before 5.4.9, and 5.5.x before 5.5.5. TrueConf patched the vulnerabilities in 5.3.9, 5.4.9, and 5.5.5, released on June 18th.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Although TrueConf was developed by a Russian IT company, its solutions have reportedly been deployed in over 100 countries worldwide, including a small number of companies in the US, Germany, and Italy.
Federal agencies should patch the flaws by September 10th. CISA also urges all organizations to patch vulnerabilities added to its KEV catalog as soon as possible.