CVE-2026-3502
TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Apr 2, 2026
- US federal agencies must remediate it by Apr 16, 2026 (BOD 22-01)
- Attacked on the day of disclosure
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Apr 7, 2026 Apr 2, 2026 Mar 31, 2026
CVSS score7.8 / 10
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:LWeakness type (CWE)CWE-494
Vendorstrueconf
Affected products
| Vendors | Product | Versions |
|---|---|---|
| trueconf | trueconf | < 8.5.3.884 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
