Vendor
critical
threat
Active Exploitation of TrueConf Server Vulnerabilities
2 CVEsTrueConf Server versions 5.3.x, 5.4.x, and 5.5.x are vulnerable to CVE-2026-72529 and CVE-2026-72530, which are currently being exploited in the wild according to CISA KEV.
exploited
TrueConf Server 5.3 +2
2c
updated
high
threat
Head Mare APT Exploiting TrueConf Server Vulnerabilities to Deploy PhantomCore and PhantomGraph
1 rule 3 TTPs 2 CVEsThe Head Mare APT group is exploiting a chain of vulnerabilities in TrueConf Server to achieve remote code execution as SYSTEM and distribute backdoored installer packages to victims.
TrueConf Server
Head Mare
1r
3t
2c
updated
high
advisory
TrueConf Client Arbitrary Code Execution via Unverified Updates (CVE-2026-3502)
2 rules 1 TTP 1 CVE 1 IOCTrueConf Client downloads application updates without verifying integrity, allowing a network attacker to substitute a tampered payload, leading to arbitrary code execution.
TrueConf Server +1
cve-2026-3502
trueconf
rce
update
2r
1t
1c
1i
updated