Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Vulnerability ×2

DELMIA Apriso and XWiki exploitation

Updated 18.11.2025 00:41
Case score 63
Members 3 First seen 12.09.2025 14:03 Latest activity 18.11.2025 00:41

Overview

Attackers are actively exploiting **DELMIA Apriso** and **XWiki** flaws, with DELMIA Apriso spanning Release 2020 through Release 2025 and XWiki abuse reaching code execution through the SolrSearch endpoint. The available evidence also shows an XWiki attack chain that stages a downloader and then delivers a cryptocurrency miner. CISA has placed the flaws on **KEV**, Dassault Systèmes has already patched the DELMIA Apriso issues, and federal remediation deadlines are now in force. Reach is still unquantified, and the available evidence does not identify a single actor or confirm the total number of affected deployments.
Latest development Open development history 3 earlier developments CISA and VulnCheck flag active exploitation of DELMIA Apriso and XWiki flaws CISA and VulnCheck say threat actors are actively exploiting Dassault Systèmes DELMIA Apriso and XWiki, with CVE-2025-6204, CVE-2025-6205, and CVE-2025-24893 tied to code injection, missing authorization, and eval injection that can enable arbitrary code execution, privileged access, and remote code execution through /bin/get/Main/SolrSearch. VulnCheck also describes a two-stage attack chain that uses wget to stage x640 from 193.32.208[.]24:8080, writes it to /tmp/11909, and then fetches additional payloads including a cryptocurrency miner; Dassault Systèmes addressed the DELMIA Apriso flaws in early August, and several FCEB agencies must remediate them by November 18, 2025.
  1. Earlier development

    CISA warns of active exploitation of DELMIA Apriso flaws

    CISA says attackers are actively exploiting CVE-2025-6205 and CVE-2025-6204 in Dassault Systèmes DELMIA Apriso, a manufacturing operations management (MOM) and execution (MES) solution. CVE-2025-6205 is a critical missing authorization flaw that can let unauthenticated threat actors remotely gain privileged access, and CVE-2025-6204 is a high-severity code injection vulnerability that can let attackers with high privileges execute arbitrary code on vulnerable systems. Dassault Systèmes patched both flaws in early August 2025 and said they affect DELMIA Apriso from Release 2020 through Release 2025, while CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog.

  2. Earlier development

    Dassault Systèmes discloses DELMIA Apriso deserialization flaw

    Dassault Systèmes disclosed a deserialization of untrusted data vulnerability in DELMIA Apriso that may lead to remote code execution (RCE) and affects all versions from Release 2020 through Release 2025.

  3. Earlier development

    Active exploitation attempts observed against DELMIA Apriso

    On September 3, active exploitation attempts leveraging CVE-2025-5086 were observed against vulnerable DELMIA Apriso endpoints using malicious SOAP requests that loaded and executed a Base64-encoded, GZIP-compressed .NET executable embedded in XML.

Signals

Exploitation
CVEs/products
Geographic context
Remediation

Malware & tooling context

4 families · 2 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Exploitation Wave Dassault Systèmes DELMIA Apriso and XWiki active exploitation wave
Updated 29.10.2025 09:44 Lead Contribution 63
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**CISA** and **VulnCheck** say **DELMIA Apriso** and **XWiki** flaws are being exploited in the wild, expanding risk across multiple products and CVEs. The abuse can lead to **arbitrary code execution** or **privileged access**, depending on the flaw. One XWiki attack chain has already been tied to **cryptocurrency miner** delivery, showing operational use rather than isolated scanning. The wave is urgent because the impacted issues are already on the **KEV** list and remediation deadlines are now in force.

Vulnerability Dassault Systèmes DELMIA Apriso MOM deserialization flaw (CVE-2025-5086)
Updated 12.09.2025 14:03 Context
Exploitation Active Exploitation CVSS 9.0 Critical Patch Patch Available

**CVE-2025-5086** in **Dassault Systèmes DELMIA Apriso MOM** is now **actively exploited**, putting **Release 2020 through Release 2025** deployments at risk of **remote code execution**. The flaw is a **deserialization of untrusted data** vulnerability, and CISA added it to the **KEV** catalog because exploitation is already being observed. **FCEB** agencies were told to apply the required updates by **October 2, 2025**.

Vulnerability DELMIA Apriso actively exploited authorization and code injection flaws (multiple vulnerabilities)
Updated 28.10.2025 20:59 Context
Exploitation Active Exploitation Exploit No Known Public Exploit CVSS 9.1 Critical Patch Patch Available

**DELMIA Apriso** flaws **CVE-2025-6205** and **CVE-2025-6204** are now **actively exploited**, creating risk of **unauthenticated privileged access** and **arbitrary code execution** on unpatched systems. **Dassault Systèmes** said it patched both issues in **early August 2025** and that they affect **Release 2020 through Release 2025**. **CISA** added the two vulnerabilities to its **Known Exploited Vulnerabilities (KEV) Catalog** and warned defenders to prioritize remediation quickly. For U.S. federal civilian agencies, the issues fall under **BOD 22-01** with a **three-week** remediation window.