CISA Warns of Active Exploits Targeting Trimble Cityworks Vulnerability

A security vulnerability affecting Trimble Cityworks’ GIS-centric asset management software has been actively exploited in the field, according to a warning from the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

This vulnerability, CVE-2025-0994 (CVSS v4 score: 8.6), is a deserialization of untrusted data flaw that may allow remote code execution by an attacker.

According to a February 6, 2025, CISA advisory, this might enable a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server by an authenticated user read more about CISA Warns of Active Exploits Targeting Trimble Cityworks Vulnerability.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *