← Browse

CVE-2026-3502

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
5.7%
92.7th percentile
CISA KEV
Listed
Added 2026-04-02 · patch by 2026-04-16
Weakness / dates
Published — · modified —

Timeline

Description

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

Official: NVD · CVE.org