Critical Security Flaw in Dassault Software: A Comedy of Errors or Cyber Catastrophe?
CISA has added a critical security flaw in Dassault Systèmes DELMIA Apriso to its Known Exploited Vulnerabilities catalog. This vulnerability, CVE-2025-5086, has a CVSS score of 9.0 and is being actively exploited from Mexico. Agencies are urged to update by October 2, 2025, to avoid cyber-spying via Trojan.MSIL.Zapchast.gen.

Hot Take:
Looks like the hackers are playing a high-stakes game of “Guess Who?” with Dassault Systèmes’ DELMIA Apriso software, using a cheat code that would make even the savviest gamer blush! Watch out, the vulnerability CVE-2025-5086 is about to hit your software harder than a cat hitting a keyboard during a Zoom call. Let’s just hope CISA can patch things up before cybercriminals start treating our data like their personal plaything.
Key Points:
- CISA adds a critical security flaw in Dassault Systèmes’ DELMIA Apriso to the KEV catalog.
- The vulnerability, CVE-2025-5086, has a CVSS score of 9.0, indicating severe risk.
- Exploitation attempts originate from an IP address in Mexico.
- Kaspersky identifies the malicious payload as Trojan.MSIL.Zapchast.gen.
- Federal agencies are urged to patch the flaw by October 2, 2025.