CVE-2026-3502
Known exploited · CISA KEV
CVSS 7.8 HIGH: trueConf Client downloads application update code and applies it without performing verification. EPSS 6% (93rd percentile).
CISA federal remediation date Apr 16
Vulnerabilities · 165 days ago
TrueConf's self-hosted video conferencing servers have a zero-day flaw in their update mechanism that lets attackers replace legitimate updates with malicious executables. This bypasses endpoint defenses because the update process is trusted and automatic, allowing malware to run on all connected endpoints without triggering alerts.
The vulnerability, tracked as CVE-2026-3502, affects TrueConf versions 8.1.0 through 8.5.2 and was fixed in 8.5.3. The threat actor TrueChaos has exploited this in attacks targeting government, defense, energy, and transportation sectors, including isolated environments. Indicators include files named poweriso.exe, 7z-x64.dll, iscsiexe.dll, and a suspicious update archive in %AppData%\Roaming\Adobe\update.7z.
This vulnerability means that even air-gapped or isolated TrueConf environments are at risk because the trusted update channel itself is compromised. Endpoint defenses that rely on trust in update mechanisms will not detect this attack, increasing the risk of persistent, stealthy intrusions in critical sectors. Threat actors can maintain long-term access by abusing the update process.
Known exploited · CISA KEV
CVSS 7.8 HIGH: trueConf Client downloads application update code and applies it without performing verification. EPSS 6% (93rd percentile).
CISA federal remediation date Apr 16
5 sources covering this story
TrueConf Zero-Day Exploited in Asian Government Attacks
A Chinese threat actor exploited the video conferencing platform to perform reconnaissance, escalate privileges, and execute additional payloads.
TrueConf zero-day vulnerability exploited to target government networks - Help Net Security
A zero-day vulnerability in the TrueConf client application was exploited to deliver malware through a compromised update process.
Hackers exploit TrueConf zero-day to push malicious software updates
Hackers have targeted TrueConf conference servers in attacks that exploit a zero-day vulnerability, allowing them to execute arbitrary files on all connected endpoints.
TrueConf Zero-Day Exploited in Attacks on Southeast Asian Government Networks
CVE-2026-3502 (CVSS 7.8) exploited in early 2026 via TrueConf updates, enabling Havoc malware deployment across government networks
The investigation led to the discovery of a zero-day vulnerability in the TrueConf client, tracked as CVE-2026-3502 with a CVSS score of 7.8.
Part of the PlainSec briefing for 2026-04-21