Exploitation Wave
Vulnerability ×2
DELMIA Apriso and XWiki exploitation
Updated 18.11.2025 00:41
Case score 63
Score breakdown
- Total
- 63
- Lead score
- 63
- Support bonus
- +0 / 20
- Scoring support
- 0
- Context members
- 2
Top contributors
- Exploitation Wave Base activity for the active exploitation wave across DELMIA Apriso and XWiki. base
- Vulnerability Adds the later DELMIA Apriso exploitation and remediation context for **CVE-2025-6204** and **CVE-2025-6205**. context
- Vulnerability Confirms earlier active exploitation of **CVE-2025-5086** in DELMIA Apriso and adds the earlier KEV deadline. context
Case score 63
Members 3
Latest activity 18.11.2025 00:41
Active exploitation
KEV: CISA KEV
Patch available
CVSS: 9.8 Critical
Active exploitation
KEV: CISA KEV
Patch available
CVSS: 9.8 Critical
Members 3
First seen 12.09.2025 14:03
Last seen 29.10.2025 09:44
Updated 18.11.2025 00:41
Overview
Attackers are actively exploiting **DELMIA Apriso** and **XWiki** flaws, with DELMIA Apriso spanning Release 2020 through Release 2025 and XWiki abuse reaching code execution through the SolrSearch endpoint. The available evidence also shows an XWiki attack chain that stages a downloader and then delivers a cryptocurrency miner.
CISA has placed the flaws on **KEV**, Dassault Systèmes has already patched the DELMIA Apriso issues, and federal remediation deadlines are now in force. Reach is still unquantified, and the available evidence does not identify a single actor or confirm the total number of affected deployments.
Attackers are actively exploiting **Dassault Systèmes DELMIA Apriso** and **XWiki**, turning separate product flaws into a live exposure story. **CVE-2025-6204** and **CVE-2025-6205** affect DELMIA Apriso Release 2020 through Release 2025, while **CVE-2025-24893** lets a guest user trigger remote code execution through the XWiki **/bin/get/Main/SolrSearch** endpoint. CISA added the DELMIA Apriso flaws and the XWiki flaw to the **Known Exploited Vulnerabilities** catalog, confirming active abuse. The available evidence also shows a two-stage XWiki attack chain that stages a downloader, executes further payloads, and has delivered a cryptocurrency miner.
Dassault Systèmes said it patched the DELMIA Apriso issues in early August 2025, and CISA placed **CVE-2025-5086** on the KEV list after earlier exploitation against the same product. Federal Civilian Executive Branch agencies must meet the **November 18, 2025** deadline for the DELMIA Apriso flaws, and the XWiki entry carries a **November 20, 2025** deadline. Available evidence shows XWiki abuse dating back to March 2025, but it does not quantify reach or confirm how many deployments were compromised. Defenders should hunt for requests to the Apriso and XWiki endpoints, downloader artifacts, and miner activity, while applying vendor mitigations or removing exposure where mitigation is unavailable.