Vulnerability Intelligence Report
TrueConf Client Update Integrity Verification Bypass
CVE-2026-3502
TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.3
Impact Score:6.0
EPSS Probability:5.75%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-494 ↗CWE-494: Download of Code Without Integrity Check.
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| TrueConf | TrueConf Client | TrueConf Client versions 8.1.0 through 8.5.2 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Check Point Software Ltd. · Vendor · Israel |
| Reserved | 2026-03-03T21:18:35 |
| Published | 2026-03-30T18:05:42 |
| Last Updated | 2026-04-03T03:55:23 |
Community Chatter & Buzz