CVE-2026-3502: listed in the CISA KEV catalog

CVE-2026-3502 · CVSS 7.8 HIGH · EPSS 6% · KEV 2026-04-02

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

Is CVE-2026-3502 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-3502

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.