high Known exploitedREV. 01
CVE-2026-3502TrueConf Client — update installed without an integrity check
The TrueConf Client fetches its update and installs it without confirming the payload is genuine, so anyone able to influence the update path substitutes their own and has it run as the updater.
Read the risk
THE VITAL STATS- CVSS score
- 7.8/ 10 CVSS v3.1
- EPSS probability
- 6% Likelihood of exploitation
- Attack complexity
- Low Conditions needed to exploit
- Known exploited
- Yes — CISA KEV
- CVE published
- 2026-03-30
- Added to KEV
- 2026-04-02
- Exploit published
- Not recorded
- Confidence
- high
- Kill chain
- initial access
- MITRE ATT&CK
- —
- Severity
- high
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
Attacker needsA position on the network path the client uses to fetch its updates.
Fixed inTrueConf Client 8.5
Behind the card
3 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02CISACISA Known Exploited Vulnerabilities catalogcisa.gov
- 03Writeupresearch.checkpoint.comresearch.checkpoint.com
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_at | nvd.nist.gov | 2026-09-24 | scrty-crds-pipeline/0.1 | high |
| exploitation.known_exploited, exploitation.kev_added | cisa.gov | 2026-09-24 | scrty-crds-pipeline/0.1 | high |
| epss | api.first.org | 2026-09-24 | scrty-crds-pipeline/0.1 | high |
| title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisites | nvd.nist.gov | 2026-09-24 | claude-code | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.