TeleMessage Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for TeleMessage products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
3
In CISA KEV
3
Beyond CISA KEV
0
Sensor Observed
0
Virtual Patch Available
0
TeleMessage KEVs Added by Year
3 TeleMessage KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2025-47729
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is... |
archiving backend | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-48928
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which... |
service | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2025-48927
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in... |
service | Confirmed | In CISA | 01 Jun 2026 |
Common Vulnerability Classes (CWE)
- CWE-1188 — Initialization of a Resource with an Insecure Default 1
- CWE-528 — Exposure of Core Dump File to an Unauthorized Control Sphere 1
- CWE-912 — Hidden Functionality 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology