Trueconf
Vendor:
First CVE: Dec 30, 2025 · Active for under a year
2
Total CVEs
More Total CVEs than 49% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
7.5
Avg CVSS
Higher Avg CVSS than 49% of tracked products
50.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Trueconf over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 30, 2025
6 months ago
Most Recent CVE
Mar 30, 2026
118 days ago
CVE Severity & Scoring
Trueconf2 CVEs
100%
All CVEs352,713 CVEs
45%
40%
11%
High
Attack Vector
Local1 (50.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (50.0%)
Attack Complexity
Low2 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (50.0%)
Unknown0 (0.0%)
Required1 (50.0%)
Privileges Required
Low1 (50.0%)
High1 (50.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3502HIGH TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tam | Mar 30, 2026 | 7.8 | 75 | YES | NO |
CVE-2025-66835HIGH TrueConf Client 8.5.2 is vulnerable to DLL hijacking via crafted wfapi.dll allowing local attackers to execute arbitrary code within the user's context. | Dec 30, 2025 | 7.1 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (2 CVEs).
CISA KEV
1 CVE
50.0% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (2 CVEs).
Media Mentions
Signals from CVEs in this product scope (2 CVEs).
Top CNAs Publishing CVEs For Trueconf
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.5.2 | 1 | 7.1 | 0.2% | 0 | 0 |