TeleMessage Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for TeleMessage products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

3

In CISA KEV

3

Beyond CISA KEV

0

Sensor Observed

0

Virtual Patch Available

0

TeleMessage KEVs Added by Year

Loading...

3 TeleMessage KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-47729

The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is...

Confirmed In CISA 01 Jun 2026
CVE-2025-48928

The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which...

Confirmed In CISA 01 Jun 2026
CVE-2025-48927

The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in...

Confirmed In CISA 01 Jun 2026

Common Vulnerability Classes (CWE)

  • CWE-1188 — Initialization of a Resource with an Insecure Default 1
  • CWE-528 — Exposure of Core Dump File to an Unauthorized Control Sphere 1
  • CWE-912 — Hidden Functionality 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology