logo

CISA Adds TrueConf Vulnerability to KEV Catalog Following Active Exploitation

ID: ee472c48-7bf0-5e20-bbaa-cb9f1bee12d1

STIX ID: report--ee472c48-7bf0-5e20-bbaa-cb9f1bee12d1

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-04-06

Date Updated: 2026-04-21

Author: Abinaya

...
...

CISA has added CVE-2026-3502 — a TrueConf Client “Download of Code Without Integrity Check” vulnerability enabling arbitrary code execution when updates are tampered with — to its Known Exploited Vulnerabilities catalog, citing active exploitation and requiring federal agencies to remediate by April 16, 2026; organizations are advised to apply vendor mitigations, update or discontinue the product if patches are unavailable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.