{"id":"CVE-2026-3502","vendor_project":"TrueConf","product":"Client","vulnerability_name":"TrueConf Client Download of Code Without Integrity Check Vulnerability","date_added":"2026-04-02","due_date":"2026-04-16","known_ransomware_use":"Unknown","short_description":"TrueConf Client contains a download of code without integrity check vulnerability. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.","required_action":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cwes":"CWE-494","cvss_version":"3.1","cvss_severity":"HIGH","cvss_vector":"CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L","nvd_published":"2026-03-30","nvd_status":"Analyzed","epss":0.05746,"epss_percentile":0.92733,"cvss_score":7.8,"days_published_to_kev":3,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2026-3502","by":"CyberMax"}