Critical CVE-2025-5086 in DELMIA Apriso Actively Exploited, CISA Issues Warning
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-5086 | Deserialization of Untrusted Data RCE in Dassault Systèmes DELMIA Apriso CVE-2025-5086 is a deserialization of untrusted data flaw (CWE-502) in Dassault Systèmes DELMIA Apriso that can be reached over the network without privileges or user interaction, though with high attack complexity (CVSS 3.1 score 9.0). By feeding crafted serialized data to the application, an attacker can achieve remote code execution on the affected system, with high impact to confidentiality, integrity, and availability across scope. Any organization running DELMIA Apriso from Release 2020 through Release 2025 is in scope, including manufacturing execution deployments that expose the software to untrusted traffic. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-09-11, and SANS ISC has reported observed exploit attempts; the EPSS probability of exploitation within 30 days is 91.9%. Do: Identify all DELMIA Apriso Release 2020 through Release 2025 deployments in your environment and upgrade to the patched releases specified in the Dassault Systèmes security advisory, as required by CISA KEV/BOD 22-01 guidance. Check whether any Apriso instances are internet-facing or reachable from untrusted networks, since SANS has observed active exploit attempts. If patching is not immediately possible, apply mitigations per vendor instructions or discontinue use of the product, and prioritize it given the 9.0 CVSS score and active exploitation. | 9.0 | 92% | KEV PoC |
| moderatelikely thousands of deployments worldwide (roughly 1k–10k systems), with the internet-exposed subset smaller since MES servers are often internal |
Full article323 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 12, 2025Vulnerability / Cyber Espionage
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting Dassault Systèmes DELMIA Apriso Manufacturing Operations Management (MOM) software to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerability, tracked as CVE-2025-5086, carries a CVSS score of 9.0 out of 10.0. According to Dassault, the issue impacts versions from Release 2020 through Release 2025.
"Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability that could lead to a remote code execution," the agency said in an advisory.
The addition of CVE-2025-5086 to the KEV catalog comes after the SANS Internet Storm Center reported seeing exploitation attempts targeting the flaw that originate from the IP address 156.244.33[.]162, which geolocates to Mexico.
The attacks involve sending an HTTP request to the "/apriso/WebServices/FlexNetOperationsService.svc/Invoke" endpoint with a Base64-encoded payload that decodes to a GZIP-compressed Windows executable ("fwitxz01.dll"), Johannes B. Ullrich, the dean of research at the SANS Technology Institute, said.
Kaspersky has flagged the DLL as "Trojan.MSIL.Zapchast.gen," which the company describes as a malicious program designed to electronically spy on a user's activities, including capturing keyboard input, taking screenshots, and gathering a list of active applications, among others.
"The collected information is sent to the cybercriminal by various means, including email, FTP, and HTTP (by sending data in a request)," the Russian cybersecurity vendor added.
Zapchast variants, according to Bitdefender and Trend Micro, have been distributed via phishing emails bearing malicious attachments for over a decade. It's currently not clear if "Trojan.MSIL.Zapchast.gen" is an improved version of the same malware.
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are advised to apply the necessary updates by October 2, 2025, to secure their networks.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/09/critical-cve-2025-5086-in-delmia-apriso.html