Critical vulnerabilities actively exploited

The United States Cybersecurity and Infrastructure Security Agency (CISA) has repeatedly added vulnerabilities affecting DELMIA Apriso, a Manufacturing Operations Management (MOM) and Manufacturing Execution System (MES) platform published by Dassault Systèmes, to its catalog of vulnerabilities known to be actively exploited (Known Exploited Vulnerabilities, KEV).

The first entry occurred on September 12, 2025, with the addition of the flaw CVE-2025-5086, rated with a CVSS score of 9.0 out of 10. A second wave of additions followed on October 29, 2025, including other vulnerabilities affecting DELMIA Apriso. Inclusion in the KEV catalog means that CISA has concrete evidence indicating that these flaws are being exploited in the wild by malicious actors.

A risk of exposure of sensitive data

DELMIA Apriso is a platform used by many manufacturers to orchestrate and manage their manufacturing operations. Compromise of this type of system can provide attackers with privileged access to operational data, as well as personal information about employees — names, identifiers, organizational data, and even contractual information.

Malicious actors who exploit such critical vulnerabilities often perform data exfiltration before selling or publishing it on darknet forums as part of extortion campaigns. This pattern, well documented by cybersecurity researchers, has become a major vector for corporate data leaks.

⚠️ At this stage, CyberBar has not independently confirmed the existence of a specific and widespread leak of Dassault Systèmes employee data on the darknet. The information below relates to confirmed vulnerabilities that are actively exploited and the resulting exposure risk.

A tense cybersecurity context for the Dassault group

This alert comes in an already sensitive context for the Dassault group. In February 2025, ZATAZ revealed a case of alleged espionage at Dassault Aviation: a 19-year-old temporary worker employed on the Rafale assembly line in Cergy had been taken into custody for potentially filming the combat aircraft with camera glasses as part of an investigation for "jeopardizing the essential interests of the nation."

Earlier, in December 2020, Dassault Falcon Jet (DFJ) had been the victim of a cyberattack carried out by the ransomware group Ragnar Locker, which exposed personal data of current and former employees, as well as their spouses. The attackers exploited the vulnerability nicknamed "Shitrix" (CVE-2019-19781) affecting Citrix ADC/Gateway.

These precedents illustrate the attractiveness of the Dassault group to cybercriminals and state actors, whether it concerns industrial espionage or financial extortion.

Security recommendations

In the face of the active exploitation of DELMIA Apriso vulnerabilities, organizations using this platform should:

  • Immediately apply patches released by Dassault Systèmes;
  • Check the internet exposure of DELMIA Apriso instances and restrict access to only necessary internal networks;
  • Monitor logs for signs of abnormal activity or data exfiltration;
  • Implement network segmentation between MOM/MES systems and the rest of the IT infrastructure;
  • Audit access and ensure that the principle of least privilege is applied.

CISA imposes a rapid remediation timeline for federal agencies regarding vulnerabilities in the KEV catalog (often within 2 to 3 weeks). Private companies are strongly encouraged to follow the same pace.

In summary

The repeated listing of DELMIA Apriso vulnerabilities in the CISA KEV catalog confirms that Dassault Systèmes, as a leading industrial software publisher, is at the heart of critical cybersecurity issues. The active exploitation of these flaws can lead to the compromise of production systems and the exfiltration of sensitive data — including employee-related information — with a real risk of dissemination on the darknet. Vigilance and rapid system updates remain the first defenses against this threat.