CVE-2025-48929: Smarsh TeleMessage

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later date if discovered by an adversary.

Affected products

  • Smarsh TeleMessage: up to and including 2025-05-05

Published 2025-05-28. Last modified 2026-06-17.