Security
Loading…

CVE-2026-3502

UNKNOWNKnown Exploited
Description

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

Timeline
Published:April 2nd, 2026 12:00 AM
Last modified:April 2nd, 2026 12:00 AM
Added to KEV:April 2nd, 2026
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

TrueConf

Products

Client
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute