high Code Vulnerability zero-day

TrueConf Zero-Day Exploited by Chinese APT (TrueChaos)

CVECVE-2026-3502
Severityhigh
Statusopen
DateApril 2, 2026
AffectsTrueConf Windows client (on-premises video conferencing)
Sourcethehackernews.com

Details

CVSS 7.8. Code integrity bypass in TrueConf’s update mechanism. Attacker controlling the on-premises server can push arbitrary code to all connected endpoints. Exploited against Southeast Asian government entities using Havoc C2. CISA added to KEV — federal patch deadline April 16. Fix: TrueConf 8.5.3.