Hacking IncidentsHigh

TrueConf Client Zero-Day CVE-2026-3502 Exploited in TrueChaos Campaign

Tuesday, April 7, 2026
Southeast Asia
NVD + CISA KEV + The Hacker News

Summary

A high-severity zero-day vulnerability (CVE-2026-3502) in TrueConf video conferencing client was exploited in a campaign dubbed TrueChaos targeting government entities in Southeast Asia. The flaw allows attackers to distribute tampered software updates and execute arbitrary code.

Threat Analysis

CVE-2026-3502 is a download-of-code-without-integrity-check vulnerability (CWE-494) in TrueConf Client video conferencing software. The flaw was exploited as a zero-day in a campaign named "TrueChaos" attributed to a Chinese-nexus threat actor, targeting government entities in Southeast Asia beginning in early 2026. The vulnerability allows attackers to distribute tampered update payloads that execute arbitrary code on victim systems, effectively turning the software update mechanism into an attack vector. CISA added CVE-2026-3502 to its Known Exploited Vulnerabilities catalog on April 2, 2026, with a remediation due date of April 16, 2026. The campaign represents a sophisticated supply-chain style attack leveraging trusted software update channels. Recommended mitigations: Apply available TrueConf patches immediately, verify software update integrity, restrict TrueConf update server access, and monitor for anomalous update activity in government networks.

Last updated: Apr 7, 2026, 08:18 AM

Daily Intelligence

Stay Ahead of Threats

Subscribe to receive daily threat briefings delivered to your inbox. Be the first to know about emerging security risks.

No spamUnsubscribe anytimeDaily at 9 AM