thehackernews.com 3/31/2026, 4:53:44 PM · via preferred

TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks

CISA Adds CVE-2026-3502 to Known Exploited Vulnerabilities Catalogue

according to Known Exploited Vulnerabilities Catalog, the entry for TrueConf is CVE-2026-3502, described as a Client Download of Code Without Integrity Check Vulnerability. An attacker who can influence the update delivery path can substitute a tampered update payload, potentially leading to arbitrary code execution in the context of the updating process or…

First seen 2026-03-31T13:27:24.648Z · Last seen 2026-04-02T21:38:25.848Z

CyberSIXT Evidence Panel
Primary Source cve.org
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A high-severity flaw in the TrueConf client has been exploited in the wild as a zero-day in a campaign targeting government networks in Southeast Asia, tracked as TrueChaos. The vulnerability, CVE-2026-3502 (CVSS 7.8), stems from a lack of integrity checking when fetching update code, allowing a tampered update to be distributed and arbitrary code to run. It has been patched in the TrueConf Windows client starting with version 8.5.3, released earlier in March 2026.

According to Check Point, the flaw enables an attacker who controls an on-premises TrueConf server to substitute the update package and spread malicious files to all connected endpoints, exploiting the client’s updater validation.

The TrueChaos activity appears to weaponise this by deploying the Havoc open-source C2 framework on vulnerable machines, with attribution described as moderate confidence to a Chinese-nexus threat actor; attacks were first recorded by the firm at the start of 2026, using DLL side-loading and a trusted update flow to widen the compromise.

View Primary Source Via thehackernews.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline