RaqibCTI
CVE

CVE-2026-3502

P2
TrueConf Client Download of Code Without Integrity Check Vulnerability
TrueConf · Client
Date added (CISA)
2026-04-02
Remediation due
2026-04-16
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

Source: NVD ↗ · CISA KEV Catalog ↗