logo

U.S. CISA adds a flaw in TrueConf Client to its Known Exploited Vulnerabilities catalog

ID: f1217cf3-bced-5a81-ab96-04449b72d484

STIX ID: report--f1217cf3-bced-5a81-ab96-04449b72d484

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-04-04

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added CVE-2026-3502 — a TrueConf Client flaw that allows unverified updates to be installed — to its Known Exploited Vulnerabilities catalog after reports that attackers compromised on‑premises TrueConf update servers to push malicious updates (delivering the Havoc framework) to government video‑conferencing deployments; Check Point calls the activity Operation TrueChaos, links it to a China‑aligned actor, and CISA ordered federal remediation by April 16, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.