TrueConf Server falls with no authentication on port 4307, and Head Mare grafts PhantomCore onto it
CVE-2026-72529 (CVSS 9.8) and CVE-2026-72530 joined CISA’s KEV catalog on August 20, 2026, six weeks after a patch the Head Mare campaign already worked around. TrueConf Server operators must patch, then prove their server was not turned into a malware distribution relay.