CVE-2026-3502
Known exploited · CISA KEV
CVSS 7.8 HIGH: trueConf Client downloads application update code and applies it without performing verification. EPSS 6% (93rd percentile).
CISA federal remediation date Apr 16
Vulnerabilities & Exploits · APT / Espionage
Chinese threat actors are exploiting CVE-2026-3502, a vulnerability in TrueConf Client's auto-update mechanism that lacks update verification. This flaw lets attackers push malicious updates through the trusted channel, delivering Havoc pentest tools and ShadowPad backdoors. The campaign, named TrueChaos, targets government entities in Southeast Asia and uses Alibaba and Tencent infrastructure for persistence.
CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by April 16, 2026. The presence of implants delivered via legitimate updates means defenders must assume compromise on vulnerable systems, not just apply the patch. Incident response should include forensic imaging, credential rotation, and network detection for Havoc and ShadowPad activity.
1 source · Apr 3
Known exploited · CISA KEV
CVSS 7.8 HIGH: trueConf Client downloads application update code and applies it without performing verification. EPSS 6% (93rd percentile).
CISA federal remediation date Apr 16
The Record from Recorded Future
CISA gives agencies two weeks to patch video conferencing bug exploited by Chinese hackers
A bug in a popular line of video conferencing software is being exploited by hackers, prompting the U.S.
originalPart of the PlainSec briefing for 2026-04-04
Every edition of this story: Chinese Hackers Exploit TrueConf Auto-Update to Deploy Espionage Tools