CISA Adds One Known Exploited ... Note

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added a new vulnerability, CVE-2025-5086, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability affects Dassault Systèmes DELMIA Apriso and is classified as a deserialization of untrusted data vulnerability. Such vulnerabilities are commonly exploited by cyber actors and present considerable risks to federal systems. The KEV Catalog was established by Binding Operational Directive (BOD) 22-01 to list vulnerabilities with significant risk. BOD 22-01 mandates that Federal Civilian Executive Branch (FCEB) agencies must fix these identified vulnerabilities by a set deadline. This directive aims to protect FCEB networks from ongoing cyber threats. While BOD 22-01 specifically targets FCEB agencies, CISA strongly recommends that all organizations address KEV Catalog vulnerabilities. Prioritizing these remediations is crucial for effective vulnerability management and reducing cyberattack exposure. CISA will continue to update the KEV Catalog with new vulnerabilities that meet their established criteria. This ongoing process ensures that organizations are aware of and can act against the most pressing cyber threats.