Daily Wire · Free EditionConfirmed Threats. Zero Noise.

The Exploit Bulletin

What Security Teams Must Act On Today

From the edition of

Wednesday, August 19, 2026

Remote Code ExecutioncriticalCVSS 9.5CVE-2026-72530CVE-2026-72529

Unauthenticated script execution and sandbox escape in TrueConf Server over port 4307 hand attackers the host (CVE-2026-72530)

CISA's SSVC decision is 'active' for both flaws and Kaspersky confirmed Head Mare is chaining them in live attacks, so unpatched TrueConf hosts exposed on port 4307 face full system compromise this week.

TrueConf Server exposes a critical function over 4307/TCP without authentication, letting a remote attacker execute an arbitrary script (CVE-2026-72529, CVSS 9.3); a code injection flaw then lets that script break out of the isolated scripting environment and run arbitrary code on the underlying host (CVE-2026-72530, CVSS 9.5). Kaspersky ICS-CERT observed the Head Mare group chaining both to deploy PhantomCore malware.

Affected: TrueConf Server < 5.3.9.10013 / < 5.3.9.10015; TrueConf Server 5.4.0.12689–5.4.9.10072 / 5.4.0.12700–5.4.9.10019; TrueConf Server 5.5.0.13826–5.5.5.10010 / 5.5.0.13828–5.5.5.10009

How to Test

Check your TrueConf Server build number in the admin panel against the fixed builds (5.3.9.10013/10015, 5.4.9.10072/10019, 5.5.5.10010/10009); scan your perimeter for exposed 4307/TCP and review connection logs on that port for unauthenticated script-execution requests; hunt for unexpected child processes spawned by the TrueConf service outside its scripting sandbox and for PhantomCore indicators from the Kaspersky ICS-CERT report.

How to Patch

Upgrade immediately to TrueConf Server 5.3.9.10013/10015, 5.4.9.10072/10019, or 5.5.5.10010/10009 (or later) for your branch — one upgrade fixes both flaws; until patched, block 4307/TCP from the internet and restrict it to trusted management networks.