Vulnerability record · CVE-2026-3502 · published 30 March 2026
CVE-2026-3502: TrueConf Client update download lacks integrity check, enabling code execution
Trueconf · Trueconf
TrueConf Client downloads application update code and applies it without verifying its integrity (CWE-494). An attacker who can influence the update delivery path can substitute a tampered update payload that the updater may then execute or install. Because the update mechanism is a trusted channel, this undermines the integrity of the client software itself.
Description
TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
Automated analysis
high priorityThe flaw allows code execution through a trusted update channel and is listed in CISA KEV with known exploitation, though the attack requires adjacent-network access, high privileges and user interaction.
What it is
TrueConf Client downloads application update code and applies it without verifying its integrity (CWE-494). An attacker who can influence the update delivery path can substitute a tampered update payload that the updater may then execute or install. Because the update mechanism is a trusted channel, this undermines the integrity of the client software itself.
Impact
Successful substitution of the update payload can result in arbitrary code execution in the context of the updating process or the user. The CVSS scope change (S:C) indicates the impact can extend beyond the vulnerable component.
Attack surface
The vector is adjacent network (AV:A) with high privileges required (PR:H) and user interaction required (UI:R), so the attacker must already be positioned on the adjacent network and the update must be triggered by a user. No remote unauthenticated path is described.
Exploitation
CVE-2026-3502 is listed in CISA KEV with a due date of 2026-04-16, indicating known exploitation, and a third-party advisory references 0-day exploitation against Southeast Asian government targets. EPSS 30-day probability is 0.05746 (92.7th percentile).
What to do
- Apply the vendor update referenced in the TrueConf 8.5 release notes; if no fixed version is available for your deployment, follow CISA BOD 22-01 guidance or discontinue use of the product.
- Restrict update delivery to trusted, authenticated channels and verify update payload signatures or hashes before installation where the product supports it.
- Limit adjacent-network access to update infrastructure and client update endpoints to reduce the attacker's ability to influence the delivery path.
- Monitor CISA KEV and vendor advisories for updated remediation guidance given the known exploitation.
Detection
- Monitor update process execution and file writes for unexpected or unsigned update payloads being installed by TrueConf Client.
- Alert on anomalous network connections to update delivery paths from TrueConf Client hosts, especially from adjacent-network sources.
- Review endpoint telemetry for child processes spawned by the TrueConf updater that are not part of normal update behavior.
- Correlate TrueConf Client update activity with known exploitation indicators from the referenced third-party advisory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-3502 to the Known Exploited Vulnerabilities catalog on 2 April 2026 as "TrueConf Client Download of Code Without Integrity Check Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 April 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://trueconf.com/blog/update/trueconf-8-5 | ProductRelease Notes |
| https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targets/ | Third Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-3502 | US Government Resource |
Track CVE-2026-3502 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-3502), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.