CVE-2026-3502
high · 7.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Added 2026-04-02Remediation due 2026-04-16
TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
7.8
CVSS
5.7%
EPSS (exploit prob.)
93rd
EPSS percentile
2026-03-30
Published
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
Weaknesses
CWE-494
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| trueconf | trueconf | < 8.5.3.884 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-3502