{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-3502",
  "revision": 1,
  "title": "TrueConf Client — update installed without an integrity check",
  "summary": "The TrueConf Client fetches its update and installs it without confirming the payload is genuine, so anyone able to influence the update path substitutes their own and has it run as the updater.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.8,
    "vector": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L",
    "version": "3.1"
  },
  "epss": 0.05746,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-04-02",
    "prerequisites": "A position on the network path the client uses to fetch its updates."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "TrueConf Client 8.5"
    ]
  },
  "kill_chain": "initial_access",
  "recommended_action": "Update TrueConf Client to 8.5 or later now; on machines that updated over untrusted networks, treat the host as compromised and rebuild it.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-3502",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-3502",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-3502",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-3502",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "writeup",
      "url": "https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targets/"
    }
  ],
  "published_at": "2026-03-30T19:16:27.053Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "trueconf",
    "supply-chain",
    "update-integrity",
    "kev"
  ]
}
