U.S. CISA adds a flaw in TrueConf Client to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-3502 | Arbitrary Code Execution via Unverified Updates in TrueConf Client CVE-2026-3502 is a download-of-code-without-integrity-check flaw (CWE-494) in TrueConf Client: the application downloads update code and applies it without verifying its integrity. An attacker who can influence the update delivery path can substitute a tampered update payload, and if that payload is executed or installed by the updater, arbitrary code runs in the context of the updating process or the user. The flaw is rated 7.8 (high) on CVSS 3.1 and affects TrueConf Client deployments, which are concentrated in enterprise and government video conferencing environments. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-04-02, and public reporting describes it as a zero-day used against Southeast Asian government networks by actors attributed to Chinese hackers, with CISA giving agencies roughly two weeks to remediate. Ransomware use is unknown, and no public proof-of-concept is known beyond the observed attacks; EPSS estimates a 5.7% chance of exploitation within 30 days (93rd percentile). Do: Apply the vendor's fix or mitigations per CISA's KEV required action and BOD 22-01; federal agencies had roughly two weeks from the 2026-04-02 KEV listing to remediate or discontinue use. Until patched, restrict and monitor the network path between TrueConf Clients and their update source, and check endpoints for unexpected update or installer activity and newly created processes. Identify which TrueConf Client versions are in use and confirm affected and fixed versions against the vendor's advisory, since the source data does not specify version ranges. | 7.8 | 6% | KEV |
| moderate~10k-100k endpoints (deployment-pattern estimate; no public install or scan counts available) |
Full article409 words · extracted from securityaffairs.com · click to collapse

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in TrueConf Client to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a flaw in TrueConf Client, tracked as CVE-2026-3502 (CVSS score of 7.8), to its Known Exploited Vulnerabilities (KEV) catalog.
TrueConf is a videoconferencing platform often used in secure, offline networks by governments and critical sectors, making it a valuable target.
CVE-2026-3502 is a flaw in TrueConf Client that allows it to download and install updates without verifying them. Attackers who can tamper with the update source can deliver malicious files, leading to arbitrary code execution on the system.
Researchers warn that threat actors are compromising TrueConf servers in government environments, exploiting the CVE-2026-3502 flaw to malicious updates.
Attackers replaced update files with malicious ones, tricking users into installing them. This delivered the Havoc framework, enabling control, surveillance, and persistence.
“The infections began when TrueConf client application launched, probably by a link sent to the target from the attacker. This link launched the already installed TrueConf client and presented an update prompt claiming that a newer version was available. Prior to the victim’s interaction, the attacker had already replaced the update package on the TrueConf on-premises server with a weaponize\d version, ensuring that the client retrieved a malicious file through the normal update process.” reported Check Point. “The compromised TrueConf on-premises server was operated by the governmental IT department and served as a video conferencing platform for dozens of government entities across the country, which were all supplied with the same malicious update.”
Checkpoint researchers tracked this wave of attacks as Operation TrueChaos and link it to a China-aligned threat actor with moderate confidence, citing tactics like DLL sideloading, use of Alibaba and Tencent infrastructure, and targeted victims. The same victim was also hit by ShadowPad, suggesting shared tools, access, or multiple Chinese-linked actors targeting it simultaneously.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix the vulnerability by April 16, 2026.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, US CISA Known Exploited Vulnerabilities catalog)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/190341/security/u-s-cisa-adds-a-flaw-in-trueconf-client-to-its-known-exploited-vulnerabilities-catalog.html