🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

TrueConf Zero-Day Exploitation Southeast Asian Governments (CVE-2026-3502) | MSSP Advisory

Critical🔴 KEV ALERTConfirmed
DateApril 21, 2026
CVECVE-2026-3502
CVSS Score7.8
Affectedtrueconf
📋Executive Summary
Threat actors exploited a zero-day vulnerability CVE-2026-3502 in TrueConf video conferencing software to target Southeast Asian government entities. The vulnerability scores 7.8 CVSS and allows attackers to compromise systems through legitimate TrueConf client installations. Check Point discovered this active exploitation campaign dubbed Operation TrueChaos at the beginning of 2026.
⚠️Why It Matters for MSSPs
TrueConf is deployed across MSSP client environments as remote collaboration software, making your clients direct targets for this zero-day attack. Your RMM and remote access sessions could be compromised if you use TrueConf for client communications or if it runs on your management infrastructure.
Recommended Action
Disable TrueConf software across all client environments and your own infrastructure within 24 hours until patches are available.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Zero-Day

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.