CVE-2026-3502 is a high-severity security flaw in the TrueConf client that was exploited as a zero-day in campaigns targeting government entities in Southeast Asia. The vulnerability was reported by Check Point and used to deploy the Havoc C2 framework. Organizations using TrueConf client are advised to apply patches immediately.