EUVD-2026-17162
TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 2 Apr 2026. Evidence sources: cisa_kev.
- ENISA score
- 7.8 · CVSS 3.1
- Advisory evidence
- No linked advisory details stored yet
