CVE-2026-3502

Confirmed PUBLISHED

TrueConf Client Update Integrity Verification Bypass

TrueConf · TrueConf Client

1 day faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.8 High EPSS 5.8%

At a Glance

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

cisa
CVE Published
Mar 30, 2026
Exploitation Reported
Jun 01, 2026
CVSS
7.8 High
EPSS
5.8%
Low complexity

Affected Versions

Vendor Product Version Status
TrueConf
TrueConf Client

TrueConf Client versions 8.1.0 through 8.5.2

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.