Find notable cyber news and cases, enriched with sources, timelines, and signals.
Exploitation Wave Vulnerability ×2

DELMIA Apriso and XWiki exploitation

Updated 18.11.2025 00:41
Case score 63
Case score 63 Members 3 Latest activity 18.11.2025 00:41 Active exploitation KEV: CISA KEV Patch available CVSS: 9.8 Critical
Active exploitation KEV: CISA KEV Patch available CVSS: 9.8 Critical
Members 3 First seen 12.09.2025 14:03 Last seen 29.10.2025 09:44 Updated 18.11.2025 00:41

Overview

Attackers are actively exploiting **DELMIA Apriso** and **XWiki** flaws, with DELMIA Apriso spanning Release 2020 through Release 2025 and XWiki abuse reaching code execution through the SolrSearch endpoint. The available evidence also shows an XWiki attack chain that stages a downloader and then delivers a cryptocurrency miner. CISA has placed the flaws on **KEV**, Dassault Systèmes has already patched the DELMIA Apriso issues, and federal remediation deadlines are now in force. Reach is still unquantified, and the available evidence does not identify a single actor or confirm the total number of affected deployments.