HomeSecurityCISA warns of two new TeleMessage vulnerabilities

CISA warns of two new TeleMessage vulnerabilities

The US cybersecurity agency CISA is drawing attention to two more vulnerabilities in the TeleMessage TM SGNL messaging application , urging organizations to patch them immediately.

See also: Bluetooth vulnerabilities affect popular audio devices

TeleMessage vulnerabilities

It's an app that allows you to archive messages sent via WhatsApp, Telegram, and Signal. TeleMessage recently came to the fore after former Trump national security adviser Mike Waltz was found using it on his phone. Later, dozens of government employees were also found to be using the app.

Shortly afterwards, Oregon-based communications company Smarsh, which owns Israeli-based TeleMessage, suspended all services for the app after hackers demonstrated that the lack of encryption allowed the interception of chat files.

The vulnerability, labeled CVE-2025-47729 (CVSS score: 4.9), was added to CISA's Known Exploited Vulnerabilities (KEV) list in mid-May. Now, CISA reports that two more vulnerabilities in the TeleMessage, codenamed CVE-2025-48927 and CVE-2025-48928, have already been exploited by hackers.

According to a NIST announcement , the first issue arises because the Spring Boot Actuator monitoring tool is configured with the heap dump endpoint enabled and exposed

See also: Cisco: Critical vulnerabilities in Cisco Identity Services Engine (ISE)

The second is due to the fact that the TeleMessage service is based on a JSP, where the content of the heap memory roughly corresponds to a “core dump”, which may include a password previously sent via HTTP, according to the same NIST announcement.

CISA warns of two new TeleMessage vulnerabilities
CISA warns of two new TeleMessage vulnerabilities

NIST described both vulnerabilities as “ exploited in the wild ” as early as May 2025, following revelations by hackers who explained how the use of JSP technology (over 20 years old) combined with the exposed heap dump endpoint allowed them to obtain a snapshot of the server's memory, revealing users' login details

The hackers said the entire process took about 20 minutes, demonstrating how dangerous using the TeleMessage service was.

Although the CISA directive applies exclusively to federal agencies, all organizations are advised to update and patch their TeleMessage applications as soon as possible.

See also: CISA added three new vulnerabilities to the KEV List

The TeleMessage incident highlights a serious problem often encountered in technologies used by government and business entities: the delay in updating and maintaining critical systems.

Source: securityweek

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS