• News/
  • https://www.bleepingcomputer.com/news/security/hackers-exploit-trueconf-zero-day-to-push-malicious-software-updates/

Hackers exploit TrueConf zero-day to push malicious software updates

BleepingComputer
·
Bill Toulas
·
Published Apr 1, 2026
·
Updated

Hackers have targeted TrueConf conference servers in attacks that exploit a zero-day vulnerability, allowing them to execute arbitrary files on all connected endpoints. The flaw is tracked as CVE-2026-3502 and received a medium severity score. It stems from a missing integrity check in the software’s update mechanism, which can be used to replace the legitimate update with a malicious variant. TrueConf is a video conferencing platform that can run as a self-hosted server. Although it also supports cloud deployments, it is generally designed for closed, offline environments. According to the vendor, more than 100,000 organizations transitioned to TrueConf during the COVID-19 pandemic for remote online business activities. Among TrueConf users are military forces, government agencies, oil and gas corporations, and air traffic management companies. CheckPoint researchers have been tracking a campaign they track as TrueChaos that, since the beginning of the year, has exploited CVE-2026-3502 in zero-day attacks targeting government entities in Southeast Asia. “An attacker who gains control of the on-premises TrueConf server can replace the expected update package with an arbitrary executable, presented as the current application version, and distribute it to all connected clients,” CheckPoint says. “Because the client trusts the server-provided update without proper validation, the malicious file can be delivered and executed under the guise of a legitimate TrueConf update.” The ...

Read full article

Affected Software

1 affected component
TrueConf Video Conferencing Server>=8.1.0<=8.5.2

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a zero-day vulnerability in TrueConf software being exploited by hackers to deploy malicious updates.

2

What security implications are discussed in the article?

The article highlights the risk of arbitrary file execution on connected endpoints due to the exploited vulnerability.

3

What specific vulnerability is mentioned in the article?

The vulnerability is tracked as CVE-2026-3502 and is associated with a missing integrity check.

4

What software is affected by this security issue?

The affected software is the TrueConf Video Conferencing Server.

5

What severity score is assigned to this vulnerability?

The vulnerability received a medium severity score.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203