The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog to include critical vulnerabilities affecting Dassault Systèmes DELMIA Apriso, XWiki, and VMware Aria. The DELMIA Apriso platform is impacted by two severe flaws: a code injection vulnerability (CVE-2025-6204) that allows remote command execution, and a missing authorization issue (CVE-2025-6205) enabling privilege escalation. Both vulnerabilities have been actively exploited in attacks targeting manufacturing environments, with CISA urging immediate patching and network restrictions. XWiki, an open-source collaboration tool, is also under active exploitation due to an evaluation injection flaw (CVE-2025-24893) in the /bin/get/Main/SolrSearch endpoint, which allows unauthenticated remote code execution.
CISA's warning highlights the urgent need for organizations using these platforms to apply available patches and implement mitigation strategies. The inclusion of these vulnerabilities in the KEV catalog signals that they are being leveraged in real-world attacks, increasing the risk to unpatched systems. Security teams are advised to prioritize remediation efforts to prevent potential compromise and operational disruption.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2025-6204 and CVE-2025-6205 in Dassault Systèmes DELMIA Apriso, CVE-2025-24893 in XWiki, and CVE-2025-41244 affecting VMware Aria/VMware Tools to its Known Exploited Vulnerabilities catalog. The agency's action reflected active exploitation and triggered guidance for federal agencies to remediate the issues.
Dassault Systèmes reportedly patched the DELMIA Apriso missing authorization and privilege escalation vulnerability CVE-2025-6205 in August 2025. The flaw still posed risk to organizations that had not applied the fix across affected 2020–2025 releases.
The unauthenticated XWiki remote code execution vulnerability CVE-2025-24893 began being exploited in the wild in March 2025. Reported activity commonly involved attackers using the SolrSearch evaluation injection flaw to deploy cryptocurrency miners.
The VMware local privilege escalation flaw CVE-2025-41244 was reportedly exploited in the wild by China-linked threat actor UNC5174 starting at least in mid-October 2024. The issue stems from an untrusted search path weakness in a shell script used when VMware Tools is managed by Aria Operations with SDMP enabled.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.