Zero-day vulnerability in TrueConf client for Windows

Download of code without integrity check
CVE-2026-3502

In the observed in-the-wild activity, operation тАЬTrueChaosтАЭ, the threat actor used the trusted update channel of a centrally managed on-premises TrueConf server to distribute malicious updates to multiple connected government agencies in a South Eastern country.

Vulnerability details

Advisory: SB20260331100 - Download of code without integrity check in TrueConf client for Windows

Vulnerable component: TrueConf client for Windows

CVE-ID: CVE-2026-3502

CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-494 - Download of Code Without Integrity Check

Description:

The vulnerability allows a remote attacker to compromise the affected system

The vulnerability exists due to software does not perform software integrity check when downloading updates. A remote attacker controlling a TrueConf server can supply a malicious software binary and gain full control over the affected system after a successful software update.

Note, the vulnerability is being exploited in the wild.┬а

External links:

https://research.checkpoint.com/2026/operation-truechaos-0-day-exploitation-against-southeast-asian-government-targets/