The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers exploiting a critical remote code execution flaw in DELMIA Apriso, a manufacturing operations management (MOM) and execution (MES) solution from French company Dassault Systèmes. The agency added the vulnerability, tracked as CVE-2025-5086 and rated with a critical severity score (CVSS v3: 9.0), to the Known Exploited Vulnerabilities (KEV). DELMIA Apriso is used in production processes for digitalizing and monitoring. Enterprises worlwide rely on it to schedule production, for quality management, allocate resources, warehouse management, and for integration between production equipment and business applications. It is typically deployed in automotive, aerospace, electronics, high-tech, and industrial machinery divisions, where high quality control, traceability, compliance, and a high level of process standardization are critical. The flaw is a deserialization of untrusted data vulnerability that may lead to remote code execution (RCE). The vendor disclosed the issue on June 2, noting that it impacts all versions of DELMIA Apriso from Release 2020 through Release 2025, without sharing many details. On September 3, threat researcher Johannes Ullrich published a post on SANS ISC disclosing observation of active exploitation attempts leveraging CVE-2025-5086. The observed exploit involves sending a malicious SOAP request to vulnerable endpoints that loads and executes a Base64-encoded, GZIP-...
CISA warns of actively exploited Dassault RCE vulnerability
BleepingComputer
·Bill Toulas
·Published Sep 12, 2025
·Updated
Affected Software
1 affected component
Dassault Systèmes DELMIA Apriso
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical remote code execution vulnerability in Dassault Systèmes DELMIA Apriso that is currently being exploited by hackers.
2
What security implications are discussed?
The security implications include the risk of unauthorized remote code execution, which could lead to data breaches and operational disruptions.
3
What products or software are affected?
The affected software is Dassault Systèmes DELMIA Apriso, a manufacturing operations management solution.
4
Who issued the warning about the vulnerability?
The warning was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
5
What action should users take regarding this vulnerability?
Users are advised to apply the latest security updates and patches to mitigate the risk associated with this vulnerability.