• News/
  • https://www.bleepingcomputer.com/news/security/cisa-warns-of-actively-exploited-dassault-rce-vulnerability/

CISA warns of actively exploited Dassault RCE vulnerability

BleepingComputer
·
Bill Toulas
·
Published Sep 12, 2025
·
Updated

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers exploiting a critical remote code execution flaw in DELMIA Apriso, a  manufacturing operations management (MOM) and execution (MES) solution from French company Dassault Systèmes. The agency added the vulnerability, tracked as CVE-2025-5086 and rated with a critical severity score (CVSS v3: 9.0), to the Known Exploited Vulnerabilities (KEV). DELMIA Apriso is used in production processes for digitalizing and monitoring. Enterprises worlwide rely on it to schedule production, for quality management, allocate resources, warehouse management, and for integration between production equipment and business applications. It is typically deployed in automotive, aerospace, electronics, high-tech, and industrial machinery divisions, where high quality control, traceability, compliance, and a high level of process standardization are critical. The flaw is a deserialization of untrusted data vulnerability that may lead to remote code execution (RCE). The vendor disclosed the issue on June 2, noting that it impacts all versions of DELMIA Apriso from Release 2020 through Release 2025, without sharing many details. On September 3, threat researcher Johannes Ullrich published a post on SANS ISC disclosing observation of active exploitation attempts leveraging CVE-2025-5086. The observed exploit involves sending a malicious SOAP request to vulnerable endpoints that loads and executes a Base64-encoded, GZIP-...

Read full article

Affected Software

1 affected component
Dassault Systèmes DELMIA Apriso

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical remote code execution vulnerability in Dassault Systèmes DELMIA Apriso that is currently being exploited by hackers.

2

What security implications are discussed?

The security implications include the risk of unauthorized remote code execution, which could lead to data breaches and operational disruptions.

3

What products or software are affected?

The affected software is Dassault Systèmes DELMIA Apriso, a manufacturing operations management solution.

4

Who issued the warning about the vulnerability?

The warning was issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

5

What action should users take regarding this vulnerability?

Users are advised to apply the latest security updates and patches to mitigate the risk associated with this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203