KEVIntel
7.8
CVSS
High

CVE-2026-3502

PUBLISHED

TrueConf Client Update Integrity Verification Bypass

1 day faster than CISA KEV

Exploited in the wild Low complexity
Vendor
TrueConf
Product
TrueConf Client
Published
Mar 30, 2026
EPSS
3.1% · 87% pctl

Automate this intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot data — is available programmatically for VM, SOC, and CTI workflows.

Description

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

cisa

Weaknesses (CWE)

  • Download of Code Without Integrity Check

CVSS scores

CVSS v3.1 7.8 High

CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L

Exploitation status

Exploited in the wild

Recorded 2026-06-01 12:42:57 UTC · CVE

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CVE First 2026-06-01 12:42 UTC
CISA 2026-06-02 14:02 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • KEV confirmed by CISA