CVE-2025-48927: TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability
Medium severity, CVSS 5.3. Actively exploited: in CISA KEV since 2025-07-01. EPSS: 11.1% chance of exploitation in the next 30 days.
The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.
Affected products
- Smarsh TeleMessage: affected versions not specified
Published 2025-05-28. Last modified 2026-06-17.