CVE-2025-5086: Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability
Critical severity, CVSS 9.0. Actively exploited: in CISA KEV since 2025-09-11. EPSS: 96.9% chance of exploitation in the next 30 days.
A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.
Affected products
- 3ds DELMIA Apriso: from 2020, up to and including 2025
Published 2025-06-02. Last modified 2026-06-17.