Skip to main content

CVE detail

CVE-2025-0994

Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.

CVSS 8.6 · HighBuzz score 69.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 69.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 24.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
24.0
10 evidence mentions in the snapshot
Diversity score
20.0
6 sources across 4 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
10 source links · newest first
  • A now-patched high-severity security flaw affecting Trimble Cityworks — a specialized software used by local governments in the US, utilities, and public agencies to manage their infrastructure and community services—was abused by Chinese hackers to compromise systems before a patch was available. According to a Talos intelligence report, the flaw (tracked as CVE-2025-0994) in the […]

    newswww.csoonline.comMay 23, 2025, 11:40 AM
  • A Chinese threat actor exploited a zero-day vulnerability in Trimble Cityworks to hack local government entities in the US.

    newswww.securityweek.comMay 23, 2025, 9:30 AM
  • A Chinese threat actor, tracked as UAT-6382, exploited a patched Trimble Cityworks flaw to deploy Cobalt Strike and VShell. Cisco Talos researchers attribute the exploitation of the CVE-2025-0994 in Trimble Cityworks to Chinese-speaking threat actor UAT-6382, based on tools and TTPs used in the intrusions. The vulnerability CVE-2025-0994 (CVSS v4 score of 8.6) is a […]

    newssecurityaffairs.comMay 23, 2025, 6:27 AM
  • 10th February – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 10th February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Grubhub, the US-based online food ordering and delivery platform, suffered a data breach due to unauthorized access through a compromised third-party service provider’s account. The incident exposed personal details of customers, drivers, […]

    vendorresearch.checkpoint.comFeb 10, 2025, 1:53 PM
  • Hackers are exploiting a high-severity remote code execution (RCE) flaw in Cityworks deployments — a GIS-centric asset and work order management software — to execute codes on a customers’ Microsoft web servers. In a coordinated advisory with the US Cybersecurity and Infrastructure Security Agency (CISA), Cityworks’ developer Trimble said that the vulnerability, tracked as CVE-2025-0994 […]

    newswww.csoonline.comFeb 10, 2025, 12:57 PM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Trimble Cityworks vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Trimble Cityworks vulnerability, tracked as CVE-2025-0994, to its Known Exploited Vulnerabilities (KEV) catalog. Trimble Cityworks is a GIS-centric asset management and permitting software designed for local governments, utilities, and […]

    newssecurityaffairs.comFeb 7, 2025, 9:54 PM
  • Trimble Cityworks is affected by a zero-day vulnerability that has been exploited in attacks involving the delivery of malware.

    newswww.securityweek.comFeb 7, 2025, 9:55 AM
  • No excerpt available.

    Mitigationwww.cisa.govFeb 6, 2025, 4:15 PM
  • No excerpt available.

    Mitigationwww.cisa.govFeb 6, 2025, 4:15 PM
  • No excerpt available.

    Vendor Advisorylearn.assetlifecycle.trimble.comFeb 6, 2025, 4:15 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2026-65617

    A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository…

    CVSS 8.8 · High
    2 mentions
  • CVE-2026-63077

    In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

    CVSS 9.8 · Critical
    1 mention
  • CVE-2026-15962

    The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.2.6 via deserialization of untrusted input. Thi…

    CVSS 8.8 · High
    2 mentions
  • CVE-2026-50517

    Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

    CVSS 9.9 · Critical
    1 mention
  • CVE-2026-21655

    Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.

    CVSS 8.7 · High
    3 mentions
  • CVE-2026-65497

    Administrator PHP Object Injection in Complianz <= 7.5.0 versions.

    CVSS 7.2 · High
    1 mention