ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

TrueConf zero-day vulnerability exploited to target government networks

criticalExploit / PoCimportance 60CVE-2026-3502

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-3502
Arbitrary Code Execution via Unverified Updates in TrueConf Client

CVE-2026-3502 is a download-of-code-without-integrity-check flaw (CWE-494) in TrueConf Client: the application downloads update code and applies it without verifying its integrity. An attacker who can influence the update delivery path can substitute a tampered update payload, and if that payload is executed or installed by the updater, arbitrary code runs in the context of the updating process or the user. The flaw is rated 7.8 (high) on CVSS 3.1 and affects TrueConf Client deployments, which are concentrated in enterprise and government video conferencing environments. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-02, and public reporting describes it as a zero-day used against Southeast Asian government networks by actors attributed to Chinese hackers, with CISA giving agencies roughly two weeks to remediate. Ransomware use is unknown, and no public proof-of-concept is known beyond the observed attacks; EPSS estimates a 5.7% chance of exploitation within 30 days (93rd percentile).

Do: Apply the vendor's fix or mitigations per CISA's KEV required action and BOD 22-01; federal agencies had roughly two weeks from the 2026-04-02 KEV listing to remediate or discontinue use. Until patched, restrict and monitor the network path between TrueConf Clients and their update source, and check endpoints for unexpected update or installer activity and newly created processes. Identify which TrueConf Client versions are in use and confirm affected and fixed versions against the vendor's advisory, since the source data does not specify version ranges.

7.86% KEV
  • TrueConf Client
moderate~10k-100k endpoints (deployment-pattern estimate; no public install or scan counts available)
Full article333 words · extracted from helpnetsecurity.com · click to collapse

Suspected China-nexus attackers have leveraged a zero-day vulnerability (CVE-2026-3502) in the TrueConf client application to distribute malware within government networks in Southeast Asia, Check Point researchers discovered.

TrueConf zero-day vulnerability

Malicious client update attack chain (Source: Check Point)

Trusted update mechanism turned into attack vector

TrueConf is a videoconferencing platform designed to run on private local networks (LANs) without internet access, which makes it attractive to government departments, defense institutions, and critical infrastructure operators. Consequently, the solution is an attactive target to nation-state threat actors, as well.

This attack campaign did not rely on phishing emails or exposed services. Instead, the attackers sought to compromise software already deployed inside government environments.

CVE-2026-3502 makes the TrueConf client application download updates from a centralized, on-premises server and apply them without verifying the integrity of update packages. Attackers were able to weaponize this by gaining control of the TrueConf servers of some government entities in Southeast Asia.

“The infections began when TrueConf client application launched, probably by a link sent to the target from the attacker. This link launched the already installed TrueConf client and presented an update prompt claiming that a newer version was available,” Check Point researchers explained.

“Prior to the victim’s interaction, the attacker had already replaced the update package on the TrueConf on-premises server with a weaponized version, ensuring that the client retrieved a malicious file through the normal update process,” they noted.

In observed cases, attackers used the update channel to deliver malicious payloads, which were then used to deploy the Havoc open-source post-exploitation framework. Once installed, it enabled reconnaissance, persistence, and communication with command-and-control infrastructure.

Attribution and mitigation

Check Point believes, with moderate confidence, that Operation TrueChaos is linked to a Chinese-nexus threat actor, based on overlaps in tactics, infrastructure, and targeting.

CVE-2026-3502 has been patched in TrueConf Windows client version 8.5.3, released in March 2026. Organizations running earlier versions remain exposed.

Researchers advise organizations to review systems for signs of compromise by focusing on suspicious update behavior and related artifacts.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/04/02/trueconf-zero-day-vulnerability-cyber-espionage/