DELMIA Apriso and XWiki exploitation
Case score 63
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 63
- Main story score
- 63
- Related evidence lift
- +0 / 20
- Contributing updates
- 0
- Context updates
- 2
- Exploitation Wave Base activity for the active exploitation wave across DELMIA Apriso and XWiki. main
- Vulnerability Adds the later DELMIA Apriso exploitation and remediation context for CVE-2025-6204 and CVE-2025-6205. context
- Vulnerability Confirms earlier active exploitation of CVE-2025-5086 in DELMIA Apriso and adds the earlier KEV deadline. context
Overview
Latest development Open development history CISA and VulnCheck flag active exploitation of DELMIA Apriso and XWiki flaws CISA and VulnCheck say threat actors are actively exploiting Dassault Systèmes DELMIA Apriso and XWiki, with CVE-2025-6204, CVE-2025-6205, and CVE-2025-24893 tied to code injection, missing authorization, and eval injection that can enable arbitrary code execution, privileged access, and remote code execution through /bin/get/Main/SolrSearch. VulnCheck also describes a two-stage attack chain that uses wget to stage x640 from 193.32.208[.]24:8080, writes it to /tmp/11909, and then fetches additional payloads including a cryptocurrency miner; Dassault Systèmes addressed the DELMIA Apriso flaws in early August, and several FCEB agencies must remediate them by November 18, 2025.
-
CISA warns of active exploitation of DELMIA Apriso flaws
CISA says attackers are actively exploiting CVE-2025-6205 and CVE-2025-6204 in Dassault Systèmes DELMIA Apriso, a manufacturing operations management (MOM) and execution (MES) solution. CVE-2025-6205 is a critical missing authorization flaw that can let unauthenticated threat actors remotely gain privileged access, and CVE-2025-6204 is a high-severity code injection vulnerability that can let attackers with high privileges execute arbitrary code on vulnerable systems. Dassault Systèmes patched both flaws in early August 2025 and said they affect DELMIA Apriso from Release 2020 through Release 2025, while CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog.
-
Dassault Systèmes discloses DELMIA Apriso deserialization flaw
Dassault Systèmes disclosed a deserialization of untrusted data vulnerability in DELMIA Apriso that may lead to remote code execution (RCE) and affects all versions from Release 2020 through Release 2025.
-
Active exploitation attempts observed against DELMIA Apriso
On September 3, active exploitation attempts leveraging CVE-2025-5086 were observed against vulnerable DELMIA Apriso endpoints using malicious SOAP requests that loaded and executed a Base64-encoded, GZIP-compressed .NET executable embedded in XML.