peter bassill · operator
$ cve CVE-2026-3502 JSON

CVE-2026-3502 KEV

7.8
HIGH · CVSS 3.1 · EPSS 0.3% (pctl 23)

Patch first

On CISA KEV — known exploited in the wild, due 2026-04-16.

Description

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
EPSS0.33% — more likely to be exploited than 23% of all CVEs
WeaknessCWE-494
On CISA KEVyes — remediate by 2026-04-16
Public exploitnone known
Published2026-03-30
Last modified2026-06-17

CISA KEV

NameTrueConf Client Download of Code Without Integrity Check Vulnerability
Added2026-04-02
Due2026-04-16
Vendor / productTrueConf / Client
Ransomware usenone reported

Affected (1)

VendorProduct
trueconftrueconf

References

→ the Explorer  ·  watch your stack  ·  NVD