← All CVEs

CVE-2026-3502

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added 2026-04-02Remediation due 2026-04-16

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

7.8
CVSS
5.7%
EPSS (exploit prob.)
93rd
EPSS percentile
2026-03-30
Published

CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L

Weaknesses

CWE-494

Affected products

VendorProductAffected versions
trueconftrueconf< 8.5.3.884

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-3502