news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-3502

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
7.8 High
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L
Risk score
100.0
Known exploited
CISA KEV
Published
2026-03-30
Status
Published

TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.

Weaknesses

CWE-494

Coverage 1

Advisories and references