The US cybersecurity agency CISA is drawing attention to two more vulnerabilities in the TeleMessage TM SGNL messaging application , urging organizations to patch them immediately.
See also: Bluetooth vulnerabilities affect popular audio devices

It's an app that allows you to archive messages sent via WhatsApp, Telegram, and Signal. TeleMessage recently came to the fore after former Trump national security adviser Mike Waltz was found using it on his phone. Later, dozens of government employees were also found to be using the app.
Shortly afterwards, Oregon-based communications company Smarsh, which owns Israeli-based TeleMessage, suspended all services for the app after hackers demonstrated that the lack of encryption allowed the interception of chat files.
The vulnerability, labeled CVE-2025-47729 (CVSS score: 4.9), was added to CISA's Known Exploited Vulnerabilities (KEV) list in mid-May. Now, CISA reports that two more vulnerabilities in the TeleMessage, codenamed CVE-2025-48927 and CVE-2025-48928, have already been exploited by hackers.
According to a NIST announcement , the first issue arises because the Spring Boot Actuator monitoring tool is configured with the heap dump endpoint enabled and exposed
See also: Cisco: Critical vulnerabilities in Cisco Identity Services Engine (ISE)
The second is due to the fact that the TeleMessage service is based on a JSP, where the content of the heap memory roughly corresponds to a “core dump”, which may include a password previously sent via HTTP, according to the same NIST announcement.

NIST described both vulnerabilities as “ exploited in the wild ” as early as May 2025, following revelations by hackers who explained how the use of JSP technology (over 20 years old) combined with the exposed heap dump endpoint allowed them to obtain a snapshot of the server's memory, revealing users' login details
The hackers said the entire process took about 20 minutes, demonstrating how dangerous using the TeleMessage service was.
Although the CISA directive applies exclusively to federal agencies, all organizations are advised to update and patch their TeleMessage applications as soon as possible.
See also: CISA added three new vulnerabilities to the KEV List
The TeleMessage incident highlights a serious problem often encountered in technologies used by government and business entities: the delay in updating and maintaining critical systems.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
