CVE-2025-47729: TeleMessage TM SGNL Hidden Functionality Vulnerability

Medium severity, CVSS 4.9. Actively exploited: in CISA KEV since 2025-05-12. EPSS: 0.4% chance of exploitation in the next 30 days.

The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.

Affected products

  • TeleMessage Text Message Archiver: up to and including 2025-05-05

Published 2025-05-08. Last modified 2026-06-17.