Vulnerability record · CVE-2025-5086 · published 2 June 2025
CVE-2025-5086: DELMIA Apriso deserialization of untrusted data enables remote code execution
3ds · Delmia Apriso
DELMIA Apriso from Release 2020 through Release 2025 contains a deserialization of untrusted data flaw (CWE-502) that can lead to remote code execution. The vulnerability is network reachable and requires no authentication or user interaction, making it a serious risk to exposed Apriso deployments.
Description
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.0 critical severity, active exploitation confirmed by CISA KEV and SANS, and very high EPSS probability make this an urgent patching priority.
What it is
DELMIA Apriso from Release 2020 through Release 2025 contains a deserialization of untrusted data flaw (CWE-502) that can lead to remote code execution. The vulnerability is network reachable and requires no authentication or user interaction, making it a serious risk to exposed Apriso deployments.
Impact
A successful attacker can execute arbitrary code on the affected server, potentially gaining full control of the Apriso application and its host. This can lead to data compromise, service disruption, and lateral movement within the manufacturing environment.
Attack surface
The flaw is reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N). The high attack complexity (AC:H) suggests exploitation may require specific conditions or crafted serialized data, but no authentication is needed.
Exploitation
CVE-2025-5086 is listed in CISA KEV with a due date of 2025-10-02, and EPSS indicates a 91.9% probability of exploitation in the next 30 days. A SANS ISC diary reference tagged 'Exploit' confirms active exploitation attempts.
What to do
- Apply the vendor patch or mitigation from Dassault Systèmes as soon as possible.
- If patching is not immediately possible, follow CISA KEV required actions, including discontinuing use or isolating the product.
- Restrict network access to DELMIA Apriso servers to trusted networks and block unnecessary inbound traffic.
- Monitor for and block known exploitation attempts using network and endpoint controls.
- Review and harden deserialization endpoints and input validation where feasible.
Detection
- Monitor network traffic for serialized payloads or unusual requests to Apriso endpoints.
- Inspect application and server logs for deserialization errors, unexpected process creation, or command execution.
- Use endpoint detection to alert on suspicious child processes spawned by the Apriso service.
- Hunt for known exploitation indicators from the SANS ISC diary and vendor advisories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-5086 to the Known Exploited Vulnerabilities catalog on 11 September 2025 as "Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 2 October 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.3ds.com/vulnerability/advisories | Vendor Advisory |
| https://isc.sans.edu/diary/Exploit+Attempts+for+Dassault+DELMIA+Apriso+CVE20255086/32256 | ExploitTechnical DescriptionThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-5086 | US Government Resource |
Track CVE-2025-5086 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-5086), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.