Threat actors are actively exploiting a critical unauthenticated remote template-injection vulnerability in XWiki (CVE-2025-24893), enabling arbitrary remote code execution via the /bin/get/Main/SolrSearch endpoint. VulnCheck and other security researchers observed a two-stage attack chain: the first stage downloads a payload to the target system, and the second stage executes it, ultimately deploying a cryptocurrency miner. Exploit attempts have been traced to attackers geolocated in Vietnam, and the vulnerability has been weaponized in real-world attacks since at least March 2025, according to reports from VulnCheck, CrowdSec, and Cyble.
Despite the active exploitation, CVE-2025-24893 was not initially included in the CISA Known Exploited Vulnerabilities (KEV) catalog, highlighting a lag between real-world attacks and official recognition. Technical details reveal that attackers use a crafted request to inject Groovy code, which executes a wget command to download a malicious file to /tmp/11909. Security teams are advised to monitor for exploit attempts targeting the vulnerable endpoint and to apply available patches to mitigate the risk of compromise and subsequent cryptomining activity.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
Reporting on the XWiki attacks revealed exploitation attempts against VulnCheck canaries from infrastructure geolocated to Vietnam. The activity used wget to fetch a staged payload from 193.32.208[.]24:8080 before deploying additional components for cryptomining.
CISA added the exploited vulnerabilities affecting Dassault Systèmes DELMIA Apriso and XWiki to its Known Exploited Vulnerabilities catalog, confirming they were under active attack. For the DELMIA Apriso issues, U.S. federal civilian agencies were ordered to remediate by November 18, 2025.
VulnCheck reported active exploitation of CVE-2025-24893 in XWiki, an unauthenticated remote code execution flaw in the /bin/get/Main/SolrSearch endpoint. The attacks used a two-stage chain to download and execute payloads that installed a cryptocurrency miner and killed competing miners.
Dassault Systèmes issued patches in early August 2025 for CVE-2025-6204 and CVE-2025-6205, two DELMIA Apriso vulnerabilities that can be chained for elevated privileges and full application compromise. The flaws affect releases 2020 through 2025.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.