logo

CISA Includes TrueConf Security Flaw in KEV Catalog After Exploitation in the Wild

ID: 85f42f8b-3406-518d-8486-5147ac0c2777

STIX ID: report--85f42f8b-3406-518d-8486-5147ac0c2777

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-04-03

Date Updated: 2026-04-22

Author: Divya

...
...

CISA added CVE-2026-3502 — a TrueConf Client “Download of Code Without Integrity Check” (CWE-494) that allows arbitrary code execution via tampered updates — to its Known Exploited Vulnerabilities list on April 2, 2026, citing evidence of in-the-wild exploitation and mandating federal remediation (patch by April 16, 2026) or discontinuation of the product until secured.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.