CISA Includes TrueConf Security Flaw in KEV Catalog After Exploitation in the Wild
ID: 85f42f8b-3406-518d-8486-5147ac0c2777
STIX ID: report--85f42f8b-3406-518d-8486-5147ac0c2777
Feed Name: GBHackers
Threat Score
CISA added CVE-2026-3502 — a TrueConf Client “Download of Code Without Integrity Check” (CWE-494) that allows arbitrary code execution via tampered updates — to its Known Exploited Vulnerabilities list on April 2, 2026, citing evidence of in-the-wild exploitation and mandating federal remediation (patch by April 16, 2026) or discontinuation of the product until secured.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
