Critical Security Flaw in Dassault Software: A Comedy of Errors or Cyber Catastrophe?

CISA has added a critical security flaw in Dassault Systèmes DELMIA Apriso to its Known Exploited Vulnerabilities catalog. This vulnerability, CVE-2025-5086, has a CVSS score of 9.0 and is being actively exploited from Mexico. Agencies are urged to update by October 2, 2025, to avoid cyber-spying via Trojan.MSIL.Zapchast.gen.

Pro Dashboard

Hot Take:

Looks like the hackers are playing a high-stakes game of “Guess Who?” with Dassault Systèmes’ DELMIA Apriso software, using a cheat code that would make even the savviest gamer blush! Watch out, the vulnerability CVE-2025-5086 is about to hit your software harder than a cat hitting a keyboard during a Zoom call. Let’s just hope CISA can patch things up before cybercriminals start treating our data like their personal plaything.

Key Points:

  • CISA adds a critical security flaw in Dassault Systèmes’ DELMIA Apriso to the KEV catalog.
  • The vulnerability, CVE-2025-5086, has a CVSS score of 9.0, indicating severe risk.
  • Exploitation attempts originate from an IP address in Mexico.
  • Kaspersky identifies the malicious payload as Trojan.MSIL.Zapchast.gen.
  • Federal agencies are urged to patch the flaw by October 2, 2025.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?