Hackers have targeted TrueConf conference servers in attacks that exploit a zero-day vulnerability, allowing them to execute arbitrary files on all connected endpoints. The flaw is tracked as CVE-2026-3502 and received a medium severity score. It stems from a missing integrity check in the software’s update mechanism, which can be used to replace the legitimate update with a malicious variant. TrueConf is a video conferencing platform that can run as a self-hosted server. Although it also supports cloud deployments, it is generally designed for closed, offline environments. According to the vendor, more than 100,000 organizations transitioned to TrueConf during the COVID-19 pandemic for remote online business activities. Among TrueConf users are military forces, government agencies, oil and gas corporations, and air traffic management companies. CheckPoint researchers have been tracking a campaign they track as TrueChaos that, since the beginning of the year, has exploited CVE-2026-3502 in zero-day attacks targeting government entities in Southeast Asia. “An attacker who gains control of the on-premises TrueConf server can replace the expected update package with an arbitrary executable, presented as the current application version, and distribute it to all connected clients,” CheckPoint says. “Because the client trusts the server-provided update without proper validation, the malicious file can be delivered and executed under the guise of a legitimate TrueConf update.” The ...
Hackers exploit TrueConf zero-day to push malicious software updates
BleepingComputer
·Bill Toulas
·Published Apr 1, 2026
·Updated
Affected Software
1 affected component
TrueConf Video Conferencing Server>=8.1.0<=8.5.2
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day vulnerability in TrueConf software being exploited by hackers to deploy malicious updates.
2
What security implications are discussed in the article?
The article highlights the risk of arbitrary file execution on connected endpoints due to the exploited vulnerability.
3
What specific vulnerability is mentioned in the article?
The vulnerability is tracked as CVE-2026-3502 and is associated with a missing integrity check.
4
What software is affected by this security issue?
The affected software is the TrueConf Video Conferencing Server.
5
What severity score is assigned to this vulnerability?
The vulnerability received a medium severity score.