Both bugs are reachable without authentication over TCP port 4307. CVE-2026-72529 is a missing-authentication flaw that lets a remote attacker run an arbitrary script; CVE-2026-72530 goes further, escaping the server's sandbox to execute code on the underlying host. The Head Mare group has already been chaining the pair to drop PhantomCore malware, which is what earned them a spot on CISA's catalog on August 20. The awkward part is the timing. TrueConf shipped fixes back in June, in server builds 5.3.9, 5.4.9 and 5.5.5, so anyone still reachable on port 4307 has been running a known-vulnerable release for two months. Everything from the 5.3.x line through 5.5.5 is affected. CISA's binding directive gives federal agencies until August 23 to close the auth-bypass and September 2 for the sandbox escape.