The vulnerabilities, tracked as CVE-2025-48927 and CVE-2025-48928, have been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline of July 22, 2025, for federal agencies.
/heapdump endpoint exposed. GET /heapdump HTTP/1.1 Host: vulnerable-telemessage-instance.comCISA’s Binding Operational Directive (BOD) 22-01 mandates Federal Civilian Executive Branch (FCEB) agencies to remediate these vulnerabilities by the deadline to prevent system compromise and data breaches.
While BOD 22-01 is mandatory for federal agencies, CISA strongly urges all organizations—public and private—to:
/heapdump and secure core dump files with proper permissions.Failure to address these vulnerabilities could result in unauthorized access to sensitive communications, regulatory non-compliance, and significant operational disruptions.
Organizations are advised to align their security practices with CISA’s KEV Catalog and maintain regular threat monitoring to mitigate evolving cyber risks.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates
The post CISA Warns of Exploited Vulnerabilities in TeleMessage TM SGNL Platform appeared first on Cyber Security News.
PORTLAND, Maine (AP) — Maine’s Democratic governor on Friday vetoed what would have been the…
PORTLAND, Maine (AP) — Maine’s Democratic governor on Friday vetoed what would have been the…
Federal agents draw their guns out after an incident at the annual White House Correspondents…
Sony Pictures and Amazon’s Prime Video have published an official trailer for their Spider-Noir show,…
Star Trek: Strange New Worlds Season 4 will premiere on Paramount+ on Thursday, July 23,…
Vivienne Medrano’s adult animation hit, Hazbin Hotel, will come to an end with Season 5,…
This website uses cookies.