www.cisa.gov 4/2/2026, 9:38:25 PM · via preferred

CISA Adds CVE-2026-3502 to Known Exploited Vulnerabilities Catalogue

CISA Adds CVE-2026-3502 to Known Exploited Vulnerabilities Catalogue

according to Known Exploited Vulnerabilities Catalog, the entry for TrueConf is CVE-2026-3502, described as a Client Download of Code Without Integrity Check Vulnerability. An attacker who can influence the update delivery path can substitute a tampered update payload, potentially leading to arbitrary code execution in the context of the updating process or…

First seen 2026-03-31T13:27:24.648Z · Last seen 2026-04-02T21:38:25.848Z

CyberSIXT Evidence Panel
Primary Source nvd.nist.gov
CISA KEV Listed in KEV
Patch Patch Available

ACCORDING to Known Exploited Vulnerabilities Catalog, the entry for TrueConf is CVE-2026-3502, described as a Client Download of Code Without Integrity Check Vulnerability. An attacker who can influence the update delivery path can substitute a tampered update payload, potentially leading to arbitrary code execution in the context of the updating process or user.

The entry notes the Date Added as 02 April 2026 and a Due Date of 16 April 2026, with guidance to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Related notes point to vendor resources, including update and download pages, and a NIST CVE entry for the vulnerability. Known To Be Used in Ransomware Campaigns? Unknown.

View Primary Source Via www.cisa.gov

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline