CVE-2026-3502

unknown KEV
Published 2026-04-02 · Modified 2026-04-02
CVSS v3
CVSS v2
VIR risk
1.5

Description

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

CISA KEV

Vendor
TrueConf
Product
Client
Due date
2026-04-16

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://trueconf.com/blog/update/trueconf-8-5 ; https://trueconf.com/downloads/windows.html ; https://nvd.nist.gov/vuln/detail/CVE-2026-3502

Exploits

References

Verify integrity in audit chain (admin only). AS-IS.