Critical deserialization vulnerability in DELMIA Apriso manufacturing execution system allowing remote code execution without authentication. Active exploitation observed in the wild targeting internet-facing instances.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-06-02
Added to CISA KEV: 2025-09-11 101 DAYS BETWEEN CVE AND KEV
CVE-2025-5086 is a critical vulnerability affecting Dassault DELMIA Apriso (Release 2020 through 2025) that could lead to remote code execution due to deserialization of untrusted data [1][2]. Here's a breakdown of what is known about its exploitation:
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code ...
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution. Either way, we are seeing exploits for DELMIA Apriso related issues.
Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability. Β· Attack ...
A critical deserialization flaw (CVE-2025-5086) in DELMIA Apriso could allow remote code execution. Exploit attempts have been seen in the ...
CrowdSec network telemetry also shows that exploitation of CVE-2025-5086 has significantly declined over the past week. Attack volumes are well below the long-term average, suggesting attackers are rapidly losing interest. The vulnerability appears to be falling out of active use across most threatβ¦