CVE-2026-3502
Known exploited · CISA KEV
CVSS 7.8 HIGH: trueConf Client downloads application update code and applies it without performing verification. EPSS 6% (93rd percentile).
CISA federal remediation date Apr 16
Vulnerabilities & Exploits · Zero-Day Exploit
TrueConf's self-hosted video conferencing servers have a zero-day flaw in their update mechanism that lets attackers replace legitimate updates with malicious executables. This bypasses endpoint defenses because the update process is trusted and automatic, allowing malware to run on all connected endpoints without triggering alerts.
The vulnerability, tracked as CVE-2026-3502, affects TrueConf versions 8.1.0 through 8.5.2 and was fixed in 8.5.3. The threat actor TrueChaos has exploited this in attacks targeting government, defense, energy, and transportation sectors, including isolated environments. Indicators include files named poweriso.exe, 7z-x64.dll, iscsiexe.dll, and a suspicious update archive in %AppData%\Roaming\Adobe\update.7z.
This vulnerability means that even air-gapped or isolated TrueConf environments are at risk because the trusted update channel itself is compromised. Endpoint defenses that rely on trust in update mechanisms will not detect this attack, increasing the risk of persistent, stealthy intrusions in critical sectors. Threat actors can maintain long-term access by abusing the update process.
5 sources · Apr 3
Known exploited · CISA KEV
CVSS 7.8 HIGH: trueConf Client downloads application update code and applies it without performing verification. EPSS 6% (93rd percentile).
CISA federal remediation date Apr 16
SecurityWeek
TrueConf Zero-Day Exploited in Asian Government Attacks
A Chinese threat actor exploited the video conferencing platform to perform reconnaissance, escalate privileges, and execute additional payloads.
originalHelp Net Security
TrueConf zero-day vulnerability exploited to target government networks - Help Net Security
A zero-day vulnerability in the TrueConf client application was exploited to deliver malware through a compromised update process.
originalBleepingComputer
Hackers exploit TrueConf zero-day to push malicious software updates
Hackers have targeted TrueConf conference servers in attacks that exploit a zero-day vulnerability, allowing them to execute arbitrary files on all connected endpoints.
originalPart of the PlainSec briefing for 2026-04-01
Every edition of this story: TrueConf Update Flaw Lets Attackers Reach Isolated Government Networks