
CISA Adds Critical Dassault Systèmes DELMIA Apriso Vulnerability to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Dassault Systèmes DELMIA Apriso to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability, identified as CVE-2025-5086, has a CVSS score of 9.0, indicating a high severity level. DELMIA Apriso is a Manufacturing Operations Management (MOM) platform widely used in industrial environments. The inclusion of this vulnerability in the KEV catalog signifies that it is being actively exploited in the wild, posing significant risks to organizations utilizing this software. The high CVSS score underscores the potential for severe impacts, including unauthorized access, operational disruptions, and data breaches. Given the critical nature of manufacturing operations, a compromise in DELMIA Apriso could have cascading effects on supply chains and production processes. Cybersecurity professionals should prioritize patching and mitigating this vulnerability to prevent exploitation. Organizations are advised to apply available patches from Dassault Systèmes, monitor for any signs of exploitation, and review their overall security posture, particularly around industrial control systems. This development highlights the ongoing threat to critical infrastructure and the importance of timely vulnerability management in industrial environments.