← Vulnerability feed

Vulnerability record · CVE-2025-5086 · published 2 June 2025

CVE-2025-5086: DELMIA Apriso deserialization of untrusted data enables remote code execution

3ds · Delmia Apriso

DELMIA Apriso from Release 2020 through Release 2025 contains a deserialization of untrusted data flaw (CWE-502) that can lead to remote code execution. The vulnerability is network reachable and requires no authentication or user interaction, making it a serious risk to exposed Apriso deployments.

9.0 CVSS 3.1 Critical CISA KEV since 11 Sep 2025 EPSS 97% · top 0.1% CWE-502 · Deserialization of untrusted data
9.0CVSS 3.1 base score
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.0 critical severity, active exploitation confirmed by CISA KEV and SANS, and very high EPSS probability make this an urgent patching priority.

What it is

DELMIA Apriso from Release 2020 through Release 2025 contains a deserialization of untrusted data flaw (CWE-502) that can lead to remote code execution. The vulnerability is network reachable and requires no authentication or user interaction, making it a serious risk to exposed Apriso deployments.

Impact

A successful attacker can execute arbitrary code on the affected server, potentially gaining full control of the Apriso application and its host. This can lead to data compromise, service disruption, and lateral movement within the manufacturing environment.

Attack surface

The flaw is reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N). The high attack complexity (AC:H) suggests exploitation may require specific conditions or crafted serialized data, but no authentication is needed.

Exploitation

CVE-2025-5086 is listed in CISA KEV with a due date of 2025-10-02, and EPSS indicates a 91.9% probability of exploitation in the next 30 days. A SANS ISC diary reference tagged 'Exploit' confirms active exploitation attempts.

What to do

  • Apply the vendor patch or mitigation from Dassault Systèmes as soon as possible.
  • If patching is not immediately possible, follow CISA KEV required actions, including discontinuing use or isolating the product.
  • Restrict network access to DELMIA Apriso servers to trusted networks and block unnecessary inbound traffic.
  • Monitor for and block known exploitation attempts using network and endpoint controls.
  • Review and harden deserialization endpoints and input validation where feasible.

Detection

  • Monitor network traffic for serialized payloads or unusual requests to Apriso endpoints.
  • Inspect application and server logs for deserialization errors, unexpected process creation, or command execution.
  • Use endpoint detection to alert on suspicious child processes spawned by the Apriso service.
  • Hunt for known exploitation indicators from the SANS ISC diary and vendor advisories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-5086 to the Known Exploited Vulnerabilities catalog on 11 September 2025 as "Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 2 October 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-5086 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2025-6205DELMIA Apriso missing authorization allows privileged accessDELMIA Apriso Releases 2020 through 2025 contain a missing authorization flaw (CWE-862) that lets an attacker obtain privileged access to the applica…KEVEPSS 73%analysed8.0CVE-2025-6204DELMIA Apriso code injection allows arbitrary code executionDELMIA Apriso Releases 2020 through 2025 contain an improper control of code generation (code injection) flaw, CWE-94, that can let an attacker execu…KEVEPSS 78%analysed8.8CVE-2023-21413ds delmia apriso deserialization of untrusted data vulnerabilityAn unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.EPSS 1.0%7.5CVE-2024-09353ds delmia apriso sensitive information in log file vulnerabilityInsertion of Sensitive Information into Log File vulnerabilities are affecting DELMIA Apriso Release 2019 through Release 2024EPSS 0.35%7.5CVE-2023-21403ds delmia apriso server-side request forgery (ssrf) vulnerabilityA Server-Side Request Forgery vulnerability in DELMIA Apriso Release 2017 through Release 2022 could allow an unauthenticated attacker to issue reque…EPSS 0.56%6.1CVE-2023-21393ds delmia apriso cross-site scripting vulnerabilityA reflected Cross-site Scripting (XSS) Vulnerability in DELMIA Apriso Release 2017 through Release 2022 allows an attacker to execute arbitrary scrip…EPSS 0.35%9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed

Source: NIST National Vulnerability Database (record CVE-2025-5086), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.