CVE-2026-3502Active Exploitation(trueconf / trueconf)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 20 mentions and remains active

Immediate actions

  • Patch trueconf trueconf systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-16. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-494

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • trueconf

Threat summary

  • Active exploitation appears in 86 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 108 mentions across 21 observed days

What's happening

  • Active exploitation reported across 86 signals
  • Exploit tool or code specified in 7 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 32 signals
  • Technical details provided in 58 signals
  • General: 13 classified signals
  • Disclosure: 6 classified signals
  • Peaked 18d ago at 20 mentions (2026-04-02); latest day: 1
  • 108 total mentions across 21 days

Affected systems

Vendors
Products
trueconf

Deep dive

Activity timeline108 mentions / 21d
05101520Mentions · 2026-03-31: 13Mentions · 2026-04-01: 14Mentions · 2026-04-02: 20Mentions · 2026-04-03: 18Mentions · 2026-04-04: 7Mentions · 2026-04-05: 4Mentions · 2026-04-06: 10Mentions · 2026-04-07: 2Mentions · 2026-04-08: 5Mentions · 2026-04-09: 1Mentions · 2026-04-12: 1Mentions · 2026-04-13: 1Mentions · 2026-04-15: 1Mentions · 2026-04-22: 1Mentions · 2026-04-25: 1Mentions · 2026-05-01: 1Mentions · 2026-05-06: 2Mentions · 2026-05-15: 3Mentions · 2026-07-08: 1Mentions · 2026-08-08: 1Mentions · 2026-08-12: 1PoC Mentioned / Linked · 2026-04-01: 1PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-06: 1PoC Mentioned / Linked · 2026-04-07: 1Exploit Tool / Code · 2026-03-31: 2Exploit Tool / Code · 2026-04-01: 2Exploit Tool / Code · 2026-04-03: 1Exploit Tool / Code · 2026-04-04: 2Active Exploitation · 2026-03-31: 11Active Exploitation · 2026-04-01: 12Active Exploitation · 2026-04-02: 17Active Exploitation · 2026-04-03: 18Active Exploitation · 2026-04-04: 6Active Exploitation · 2026-04-05: 2Active Exploitation · 2026-04-06: 8Active Exploitation · 2026-04-07: 2Active Exploitation · 2026-04-08: 3Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-05-15: 3Active Exploitation · 2026-07-08: 1Active Exploitation · 2026-08-08: 1Active Exploitation · 2026-08-12: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-01: 6Patch / Workaround · 2026-04-02: 5Patch / Workaround · 2026-04-03: 9Patch / Workaround · 2026-04-04: 1Patch / Workaround · 2026-04-05: 1Patch / Workaround · 2026-04-06: 7Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-03-31: 7Technical Details · 2026-04-01: 8Technical Details · 2026-04-02: 14Technical Details · 2026-04-03: 8Technical Details · 2026-04-04: 3Technical Details · 2026-04-06: 9Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 4Technical Details · 2026-04-13: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-15: 103-3104-0204-0404-0604-0804-1204-1504-2505-0607-0808-12
Signal classification4 categories
Active Exploitation
8376.9%
General
1312.0%
Disclosure
65.6%
Patch
65.6%
Referenced assets71 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-3113
Active Exploitation11Disclosure2
2026-04-0114
Active Exploitation11General2Patch1
2026-04-0220
Active Exploitation17Disclosure3
2026-04-0318
Active Exploitation17Patch1
2026-04-047
Active Exploitation6General1
2026-04-054
Active Exploitation1General2Patch1
2026-04-0610
Active Exploitation8Patch2
2026-04-072
Active Exploitation2
2026-04-085
Active Exploitation3General2
2026-04-091
General1
2026-04-121
General1
2026-04-131
Active Exploitation1
2026-04-151
Patch1
2026-04-221
Disclosure1
2026-04-251
General1
2026-05-011
General1
2026-05-062
General2
2026-05-153
Active Exploitation3
2026-07-081
Active Exploitation1
2026-08-081
Active Exploitation1
2026-08-121
Active Exploitation1
Full discourse20 posts
  • Check Point Research@_CPResearch_
    Active Exploitation

    Operation TrueChaos Zero-day exploited in the wild by Chinese-nexus actor 💥 TrueConf client CVE-2026-3502 🌏 Southeast Asian government entities 🧰 Havoc C2, DLL sideloading, UAC bypass Read more : https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targets/

    Post summary

    A Chinese‑nexus actor leveraged CVE‑2026‑3502 to compromise Southeast Asian government targets using DLL sideloading and UAC bypass. No patch, PoC, or detailed vulnerability classification is provided.

    026175239.5K
    25.1K followersView on X
  • The Hacker News@TheHackersNews
    Active Exploitation

    ⚠️ A zero-day in TrueConf let attackers spread malware through its own update system. CVE-2026-3502 (CVSS 7.8) was exploited by compromising on-prem servers, pushing tampered updates to all connected clients in government networks across Southeast Asia. 🔗 How the TrueChaos campaign weaponized software updates → https://thehackernews.com/2026/03/trueconf-zero-day-exploited-in-attacks.html

    Post summary

    CVE‑2026‑3502, a zero‑day in TrueConf’s update mechanism, was actively exploited by attackers compromising on‑prem servers to push tampered updates to government clients across Southeast Asia, and carries a CVSS score of 7.8.

    316246611.5K
    1.6M followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added TrueConf Client download of code without integrity check vulnerability CVE-2026-3502 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/IxlaBlhjoy

    Post summary

    The tweet announces that CVE-2026-3502, a TrueConf Client download integrity check flaw, has been added to a DHS known exploited vulnerabilities catalog, indicating it is actively exploited.

    21112715.2K
    298.7K followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    Check Point reveals "TrueChaos," an espionage campaign exploiting a TrueConf zero-day (CVE-2026-3502) to drop malware via fake updates. Patch to 8.5.3 now. #TrueConf #TrueChaos #ZeroDay #CyberSecurity #InfoSec #Espionage #Malware #SupplyChainAttack https://securityonline.info/trueconf-zero-day-vulnerability-cve-2026-3502-truechaos-campaign/ https://t.co/5NL3N3Tq0k

    Post summary

    Check Point reports that CVE-2026-3502 is actively exploited in the TrueChaos espionage campaign, using fake updates to drop malware, and a patch to 8.5.3 is now available.

    2401131.1K
    12.3K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Critical TrueConf flaw CVE-2026-3502 allows state-backed actors to hijack updates and infect air-gapped networks. Update to version 8.5.3 now to stay secure. https://meterpreter.org/the-trojan-meeting-how-truechaos-turns-trueconf-video-calls-into-state-sponsored-spyware/ https://t.co/WV7C1UXWNb

    Post summary

    The post alerts users to a critical TrueConf flaw that may let state-backed actors hijack updates, and urges an immediate upgrade to version 8.5.3 to mitigate the risk.

    06061418
    12.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-3502 zero-day in TrueConf allows attackers to push malicious updates to all connected clients via missing integrity checks. Chinese 🇨🇳 APT exploits flaw to target Southeast Asian government agencies through compromised conference servers. #DFIR_Radar https://t.co/2RfoqrKWpe

    Post summary

    The tweet announces ongoing exploitation of CVE-2026-3502, a zero‑day in TrueConf, by a Chinese APT targeting Southeast Asian government agencies, using missing integrity checks to push malicious updates.

    10051300
    1.7K followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    ビデオ会議製品TrueConfのゼロデイ脆弱性"TrueChaos" (CVE-2026-3502)により、東南アジアの政府機関にマルウェアが配送された。Check Point社報告。TrueConfサーバの制御を奪取している攻撃者が、更新パッケージとして任意の実行ファイルをクライアントに配布可能なもの。 https://securityonline.info/trueconf-zero-day-vulnerability-cve-2026-3502-truechaos-campaign/

    Post summary

    The post details confirmed in‑the‑wild use of the TrueConf CVE‑2026‑3502 zero‑day, where attackers exploited the update mechanism to deliver malware to Southeast Asian government agencies.

    111132.1K
    7.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Active zero-day exploitation: Chinese 🇨🇳-nexus threat actors weaponize TrueConf video conferencing update mechanism to deploy Havoc payloads against Southeast Asian government networks. CVE-2026-3502 (CVSS 7.8) exploited in Operation TrueChaos campaign. Technical breakdown: • CVE-2026-3502: TrueConf client lacks integrity validation in update process, allowing arbitrary code execution via compromised on-premises server • Attack chain: Malicious trueconf_windows_update.exe → drops poweriso.exe + 7z-x64.dll → DLL sideloading → UAC bypass via iscsicpl.exe hijacking iscsiexe.dll • C2 infrastructure on Alibaba/Tencent cloud (43.134.90[.]60, 43.134.52[.]221, 47.237.15[.]197) serving Havoc framework • Persistence via HKCU\Software\Microsoft\Windows\CurrentVersion\Run\UpdateCheck registry key • Overlapping ShadowPad activity suggests coordinated Chinese APT operations Hunt for unsigned trueconf_windows_update.exe, poweriso.exe in C:\ProgramData\PowerISO\, and process chain trueconf.exe → trueconf_windows_update.exe spawning cmd.exe with curl/winrar commands. #DFIR_Radar

    Post summary

    CVE-2026-3502 is actively exploited by Chinese APT actors using a detailed attack chain involving DLL sideloading, UAC bypass, and Havoc payloads, with no patch or PoC mentioned.

    11050441
    1.7K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(4/2追加) 🛡️No.1558 CVE-2026-3502 TrueConf Client ダウンロードコードの整合性未検証の脆弱性 ==================================== ✅概要 ・深刻度:重要 7.8 (CVSS Base) / Check Point Software Technologies Ltd. (CNA) ・種別:ダウンロードしたコードの完全性検証不備(CWE-494) ・CVSS:CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L / Check Point Software Technologies Ltd. (CNA) TrueConf Client において、更新ファイルの整合性検証が不十分な問題が存在。攻撃者が更新配信経路を操作した場合、不正なコードをクライアントに配布され、ユーザー環境で任意コードが実行される恐れがある。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:高 ✅攻撃前提条件 ・TrueConfのアップデート配信経路に影響を与えられること ・隣接ネットワーク環境上 ・高権限、ユーザー操作が必要 ✅悪用時影響 ・改ざんされたアップデートの配布 ・任意コード実行 ・機密性および完全性の侵害 ✅悪用事例等に関する公開情報 ・PoC/Exploit:一部公開(技術情報のみ) ・ITW:あり ✅関連情報 https://nvd.nist.gov/vuln/detail/CVE-2026-3502 https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targets https://www.cisa.gov/news-events/alerts/2026/04/02/cisa-adds-one-known-exploited-vulnerability-catalog #vulnerability

    Post summary

    The post reports that CVE‑2026‑3502, a critical integrity‑verification flaw in TrueConf’s client, has been added to CISA’s Known Exploited Vulnerabilities list and has seen in‑the‑wild exploitation, but no patch or functional exploitation code has been disclosed.

    010504.0K
    43.5K followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 CISA تدرج ثغرة TrueConf ضمن قائمة KEV إثر استغلالها الفعّال أدرجت وكالة الأمن السيبراني والبنية التحتية (CISA) ثغرة أمنية حرجة، المحددة بـ CVE-2026-3502، والتي تؤثر على برنامج TrueConf، ضمن قائمة الثغرات المستغلة المعروفة (KEV). يأتي هذا الإدراج تأكيداً على استغلال الثغرة فعلياً في الهجمات السيبرانية، مما يستدعي اهتماماً فورياً من المؤسسات التي تستخدم برنامج TrueConf. نظراً للمخاطر العالية التي تشكلها الثغرات المستغلة، يُنصح بشدة بتطبيق التحديثات الأمنية المتاحة بشكل عاجل لتقليل نوافذ الهجوم. 🔗 للمزيد: https://cybersecuritynews.com/cisa-trueconf-vulnerability-kev-catalog/

    Post summary

    CISA lists CVE-2026-3502 for TrueConf as a KEV, confirming it is being exploited in the wild and urging users to apply security updates promptly.

    00031395
    245 followersView on X
  • Criminal IP@CriminalIP_US
    General

    📘 April 2026 Threat Intelligence Digest​ This month’s digest highlights key threats shaping today’s evolving attack surface and real-world exploitation trends.​ 🔹 Pre-auth RCE in GNU telnetd (CVE-2026-32746)​ 🔹 TrueConf supply chain attack via update mechanism (CVE-2026-3502)​ 🔹 FIFA-themed phishing campaigns and infrastructure patterns​ 🔹 Apache ActiveMQ RCE via chained features (CVE-2026-34197)​ 🔹 FortiClient EMS exploitation with exposed management servers (CVE-2026-35616)​ 🔹 nginx-ui MCPwn: auth bypass leading to full server compromise (CVE-2026-33032)​ ​ From pre-auth vulnerabilities to supply chain attacks and phishing infrastructure, these cases show how exposure, not just vulnerabilities, drives real-world compromise.​ ​ 👉 Explore the Full Threat Intelligence Digest​ https://www.criminalip.io/knowledge-hub/search?filter=blog​ ​ #ThreatIntelligence #Cybersecurity #AttackSurface #ASM #CTI

    Post summary

    The digest lists multiple CVEs with technical details but offers no PoCs, exploit code, active exploitation evidence, or patch information, leading to a general classification.

    10020258
    4.8K followersView on X
  • Criminal IP Japan@CriminalIP_JP
    General

    📰 2026年4月 Threat Intelligence Digest​ Criminal IPブログでこの1か月間に取り上げた、注目のセキュリティトピックをまとめました。​ 4月は、脆弱性を中心にさまざまな事例を分析しています。​ ​ 👾今月のトピック​ ・Telnetの認証前RCE脆弱性(CVE-2026-32746)​ ・TrueConfサプライチェーン攻撃(CVE-2026-3502)​ ・FIFA関連フィッシングキャンペーン​ ・Apache ActiveMQ RCE脆弱性(CVE-2026-34197)​ ・FortiClient EMS脆弱性の悪用事例(CVE-2026-35616)​ ・nginx-ui MCPwn脆弱性(CVE-2026-33032)​ 👉 ブログ一覧はこちら​ https://criminalip.io/ja/knowledge-hub/search?filter=blog​ #脅威インテリジェンス #サイバーセキュリティ #脆弱性

    Post summary

    The digest lists several CVEs and related threats, but provides no PoC, exploitation details, patches, or technical specifics.

    10020163
    1.4K followersView on X
  • StealthMole.jp@StealthMole_JP
    General

    セキュリティ OSINT ハイライト — 2026年4月第1週 CVE-2026-5281 および CVE-2026-3502 の両方が複数のアドバイザリにわたって登場します。いくつかのキャンペーンの報告がマルウェアのハッシュと限定的なネットワークを提供しておりAxiosの報告に関連する 2 つの IP アドレスが含まれています。

    Post summary

    The post reports the presence of CVE-2026-5281 and CVE-2026-3502 in multiple advisories, along with campaign data such as malware hashes and two related IP addresses, but provides no details on exploitation or mitigation.

    00020249
    568 followersView on X
  • BotBauR@BotBauR
    General

    La investigación forense, realizada por Intezer, confirmó que no hubo explotación masiva conocida, pero destacó la similitud con otros ataques de cadena de suministro, como CVE-2026-3502 en TrueConf, con un CVSS de 7.8. Esto resalta patrones persistentes de ataques supply-chain y la necesidad de fortalecer las medidas de seguridad en la cadena de suministro de software. (5/6)

    Post summary

    An forensic analysis by Intezer reported no known widespread exploitation of CVE-2026-3502, noting its similarity to other supply‑chain attacks and emphasizing the need to strengthen software supply‑chain security.

    1001028
    123 followersView on X
  • Criminal IP@CriminalIP_US
    Active Exploitation

    🔎 A trusted update channel became the attack path CVE-2026-3502 shows how supply chain compromise can start from a single centralized server. Instead of targeting endpoints one by one, attackers abused the TrueConfupdate mechanism to distribute malicious files through a trusted on-premise server. Criminal IP findings: • ~360 internet-exposed TrueConfassets identified • Some exposed servers showed weak security hygiene • Centralized management nodes can become high-impact compromise points This wasn’t just a software flaw. It was a breakdown of trust in the update workflow itself. 🔎 Full analysis https://www.criminalip.io/knowledge-hub/blog/33719 #CyberSecurity #ThreatIntelligence #SupplyChainAttack #ASM #AttackSurface

    Post summary

    CVE-2026-3502 is actively being leveraged by attackers to compromise centralized TrueConf servers, demonstrating a supply‑chain attack via a trusted update channel. Patch or mitigation details are not provided in the post.

    02000221
    4.8K followersView on X
  • Criminal IP Japan@CriminalIP_JP
    Active Exploitation

    ⚙️ #TrueConf サプライチェーン攻撃事例分析(CVE-2026-3502)​ 実際の攻撃に悪用されたTrueConfのアップデート脆弱性が公開されました。CVE-2026-3502は、正規アップデートの信頼チェーンを悪用し、マルウェア配布が可能となる脆弱性です。​ ​📌ポイント​ ・中央サーバーのアップデート経路を悪用​ ・正規アップデートを装ったマルウェア配布​ ・複数エンドポイントへの同時感染が可能​ ​ 🔎 Criminal IPインサイト​ ・外部から識別可能なTrueConfサーバーが複数存在​ ・一部資産で管理ポートやSSL設定の不備を確認​ ・中央サーバー=単一侵害点かつ拡散拠点​ 本事例の本質は信頼されたアップデートフローそのものが攻撃経路へと転換された点にあります。​ 📄 詳細はこちら​ https://www.criminalip.io/ja/knowledge-hub/blog/8482 #サイバーセキュリティ #脅威インテリジェンス

    Post summary

    CVE‑2026‑3502 in TrueConf was actively exploited by hijacking the trusted update mechanism to distribute malware to multiple endpoints, as confirmed by the incident report.

    00020158
    1.4K followersView on X
  • Baibysitter@baibysitter
    General

    supply chain attacks via update systems are getting nasty. trueconf zero-day (CVE-2026-3502) is a good example.

    Post summary

    The post references CVE-2026-3502 as an example of supply‑chain risk, but it offers no further technical, exploit, or mitigation information.

    1001098
    3.1K followersView on X
  • Autumn Good@autumn_good_35
    Active Exploitation

    『We also observed that the same victim was targeted within the same time frame by ShadowPad malware framework.』🤔 CVE-2026-3502 Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targets/

    Post summary

    CVE‑2026‑3502 is being actively exploited in the Operation TrueChaos against Southeast Asian government targets, with evidence of ShadowPad malware being used on the same victim.

    10010694
    6.7K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-3502: CISA added TrueConf Client CVE-2026-3502 to KEV: an updater integrity failure enabling tampered update payloads and potential code execution.

    Post summary

    CISA has added CVE‑2026‑3502 to its KEV list, noting an updater integrity failure that could permit tampered updates and code execution, indicating that the vulnerability is likely being exploited in the wild.

    1000039
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    What happened CISA added CVE-2026-3502 to the Known Exploited Vulnerabilities (KEV) catalog on 2026-04-02, signaling active exploitation and a mandated remediation window for U.S. federal agencies CISA KEV. The vulnerability affects TrueConf Client and is tracked as…

    Post summary

    CISA’s inclusion of CVE-2026-3502 in its KEV catalog signals active exploitation and mandates a remediation window for U.S. federal agencies, yet no PoC, exploit code, patch, or technical details are provided.

    1000059
    226 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptrueconftrueconf-windows-

Explore more