LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-5086: Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 11, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 2, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-5086 to its Known Exploited Vulnerabilities catalog on Sep 11, 2025, with a federal patch deadline of Oct 2, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Dassault Systèmes DELMIA Apriso contains a deserialization of untrusted data vulnerability that could lead to a remote code execution.

CVE-2025-5086 is a deserialization of untrusted data vulnerability affecting Dassault Systèmes DELMIA Apriso. According to CISA, it could lead to remote code execution. This matters for IT and security teams because the product is commonly deployed in manufacturing and operations environments; compromise of an instance can give an attacker a foothold for further lateral movement or disruption of production systems.

Defenders should treat this as a high-priority issue for any organization running the software and confirm all technical details, including exact affected releases, against the vendor advisory.

How it works

The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data). In this class of flaw, an application accepts serialized objects or data streams from an untrusted source and reconstructs them into live objects without sufficient validation or type restrictions.

An attacker who can supply crafted input to a vulnerable deserialization endpoint or data path can embed malicious object graphs. When the application deserializes that input, the resulting objects may trigger arbitrary code execution under the privileges of the process. Public detail on the precise attack surface or required access level for CVE-2025-5086 is limited; teams must review the vendor advisory for the exact conditions under which untrusted data reaches the deserializer.

Am I affected? How to find it in your systems

Dassault Systèmes DELMIA Apriso is typically found in manufacturing execution system (MES) deployments that manage shop-floor operations, production tracking, and related workflows. It may run on-premises or in hosted environments.

If the product is used as a cloud service, also follow applicable BOD 22-01 guidance.

How to remediate

The primary remediation is to apply the mitigations or updates supplied by Dassault Systèmes. Follow the vendor instructions exactly; do not rely on generic version numbers or assumptions.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface with compensating controls:

These measures lower risk but do not eliminate it; schedule the official patch as soon as operational constraints allow.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to full system compromise and subsequent data theft or ransomware deployment, although ransomware use specifically tied to CVE-2025-5086 is not documented. If you suspect an incident, isolate the host, preserve evidence, and follow your incident-response plan. As a quick check for previously leaked credentials, you can run a free exposure scan of your email addresses against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedDassault Systèmes · DELMIA Apriso
WeaknessCWE-502
Added to CISA KEVSep 11, 2025
Federal patch deadlineOct 2, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities