CISA has identified and added two actively exploited vulnerabilities in Dassault Systèmes' DELMIA Apriso software—CVE-2025-6204 (code injection) and CVE-2025-6205 (missing authorization)—to its Known Exploited Vulnerabilities (KEV) Catalog. These flaws, affecting DELMIA Apriso releases from 2020 through 2025, allow attackers to execute arbitrary code and gain privileged access to unpatched systems, posing significant risks to organizations using this manufacturing operations management solution. CISA's Binding Operational Directive (BOD) 22-01 mandates that Federal Civilian Executive Branch agencies remediate these vulnerabilities by November 18, 2025, and strongly urges all organizations to prioritize patching to reduce exposure to cyberattacks.
Dassault Systèmes released patches for both vulnerabilities in early August 2025 and confirmed their impact across multiple product versions. CISA emphasized that these types of vulnerabilities are frequent attack vectors for malicious actors and recommended applying vendor mitigations or discontinuing use if patches are unavailable. The agency also highlighted a previous critical DELMIA Apriso remote code execution flaw (CVE-2025-5086) added to the KEV Catalog in September, underscoring the ongoing threat to enterprises relying on this software for managing production, warehouses, and quality control operations worldwide.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
On October 28, 2025, CISA added CVE-2025-6204 and CVE-2025-6205 to its Known Exploited Vulnerabilities catalog, warning that the two Dassault Systèmes Delmia Apriso flaws were being actively exploited in the wild. The move marked CISA's second exploitation warning for Delmia Apriso in two months.
In September 2025, CISA issued an alert that attackers were actively exploiting Delmia Apriso vulnerability CVE-2025-5086. Public reporting linked exploitation attempts to delivery of a DLL named fwitxz01.dll, which some antivirus vendors flagged as malicious and Kaspersky classified as Trojan.MSIL.Zapchast.gen spyware.
In August 2025, Dassault Systèmes patched two additional Delmia Apriso vulnerabilities: CVE-2025-6204, a code injection issue that could enable arbitrary code execution, and CVE-2025-6205, a missing authorization flaw that could allow privileged access. These vulnerabilities were later identified as under active exploitation.
Dassault Systèmes released a patch in June 2025 for CVE-2025-5086, a deserialization of untrusted data vulnerability in its Delmia Apriso manufacturing operations management platform. The flaw was later reported as being actively exploited.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityaffairs.com
Open sourcecisa.gov
Open sourcebleepingcomputer.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.