ZeroHour

CVE-2026-3502

KEVmoderate

Arbitrary Code Execution via Unverified Updates in TrueConf Client

CISA: TrueConf Client Download of Code Without Integrity Check Vulnerability

CVSS 3.1
7.8 high
EPSS
6%p93
Published
()
KEV added
AI analysis

CVE-2026-3502 is a download-of-code-without-integrity-check flaw (CWE-494) in TrueConf Client: the application downloads update code and applies it without verifying its integrity. An attacker who can influence the update delivery path can substitute a tampered update payload, and if that payload is executed or installed by the updater, arbitrary code runs in the context of the updating process or the user. The flaw is rated 7.8 (high) on CVSS 3.1 and affects TrueConf Client deployments, which are concentrated in enterprise and government video conferencing environments. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-02, and public reporting describes it as a zero-day used against Southeast Asian government networks by actors attributed to Chinese hackers, with CISA giving agencies roughly two weeks to remediate. Ransomware use is unknown, and no public proof-of-concept is known beyond the observed attacks; EPSS estimates a 5.7% chance of exploitation within 30 days (93rd percentile).

What to do: Apply the vendor's fix or mitigations per CISA's KEV required action and BOD 22-01; federal agencies had roughly two weeks from the 2026-04-02 KEV listing to remediate or discontinue use. Until patched, restrict and monitor the network path between TrueConf Clients and their update source, and check endpoints for unexpected update or installer activity and newly created processes. Identify which TrueConf Client versions are in use and confirm affected and fixed versions against the vendor's advisory, since the source data does not specify version ranges.

Affected
TrueConf Client
Estimated exposure
moderate~10k-100k endpoints (deployment-pattern estimate; no public install or scan counts available) — TrueConf Client is an enterprise/government video conferencing client rather than a mass-market consumer app, and such deployments typically run thousands of seats per agency or organization, implying an installed base on the order of tens…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

CISA Known Exploited Vulnerability
Affected
TrueConf Client
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
trueconf
Products
trueconf
Weakness
CWE-494
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L

In the news