CISA Alerts About Ongoing Exploitation in Trimble Cityworks Vulnerability Resulting in IIS Remote Code Execution

It has been cautioned by the Cybersecurity and Infrastructure Security Agency (CISA) of the United States that a security vulnerability in Trimble Cityworks GIS-centric asset management software is currently being actively exploited in real-world scenar

It has been cautioned by the Cybersecurity and Infrastructure Security Agency (CISA) of the United States that a security vulnerability in Trimble Cityworks GIS-centric asset management software is currently being actively exploited in real-world scenarios.
The specific vulnerability referred to is CVE-2025-0994 (CVSS v4 score: 8.6), a flaw in handling untrusted data deserialization that may allow an intruder to execute code remotely.
“This situation may result in

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.