CVE-2026-3502

High7.8Published on March 30, 2026

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Apr 2, 2026
  • US federal agencies must remediate it by Apr 16, 2026 (BOD 22-01)
  • Attacked on the day of disclosure

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Source: CISA KEV · Apr 7, 2026 Apr 2, 2026 Mar 31, 2026

CVSS score7.8 / 10CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
Weakness type (CWE)CWE-494
Vendorstrueconf

Affected products

VendorsProductVersions
trueconftrueconf< 8.5.3.884

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database