ICS/OT

Trimble Cityworks Customers Warned of Zero-Day Exploitation

Trimble Cityworks is affected by a zero-day vulnerability that has been exploited in attacks involving the delivery of malware.

Trimble Cityworks zero-day CVE-2025-0994

US-based construction, geospatial and transportation technology solutions provider Trimble has warned customers of its Cityworks product about a vulnerability that has been exploited in the wild.

The zero-day, tracked as CVE-2025-0994 and classified as ‘high severity’, has been described as a deserialization issue that allows an external threat actor to achieve remote code execution against the target’s Microsoft Internet Information Services (IIS) web server.

Trimble Cityworks is a GIS-centric solution that organizations such as local governments, airports, utilities, and public works agencies can use to manage and maintain infrastructure. The product has been used by organizations worldwide.

The cybersecurity agency CISA has published an industrial control systems (ICS) advisory for CVE-2025-0994, likely due to its use in the industrial sector, but noted that the “Cityworks software is incapable of controlling industrial processes, and is not directly part of an ICS”.

CISA’s advisory also reveals that authentication is required to exploit the vulnerability. 

Based on the indicators of compromise (IoCs) made available by Trimble, the threat actors exploiting the Cityworks zero-day have delivered Cobalt Strike and several unidentified pieces of malware in post-exploitation activity.  

Advertisement. Scroll to continue reading.

Save the date: 2025 ICS Cyber Security Conference – October 27-30, Atlanta

It’s unclear who is behind the attacks and what types of entities have been targeted. However, Trimble received reports of “unauthorized attempts to gain access to specific customers’ Cityworks deployments”. In addition, given the types of organizations Cityworks is designed for, the zero-day has likely been exploited in targeted attacks.

The vendor pointed out that some on-premises deployments have overprivileged IIS permissions. In addition, some deployments have inappropriate attachment directory configurations. Customers have been urged to address these issues. 

Trimble has patched CVE-2025-0994 with the release of Cityworks 15.8.9 and 23.10 (with office companion). Previous versions of the software are affected.

Related: Cyber Insights 2025: OT Security

Related: Rockwell Patches Critical, High-Severity Vulnerabilities in Several Products

Related: Building Automation Protocols Increasingly Targeted in OT Attacks

Related: Researcher Says ABB Building Control Products Affected by 1,000 Vulnerabilities

Related Content

Vulnerabilities

CISA has given federal agencies only three days to patch CVE-2026-20253, which can be exploited for unauthenticated remote code execution.

Funding/M&A

The deal values industrial cybersecurity giant Dragos at $3.25 billion, and runZero and NetRise will operate under Dragos.

ICS/OT

The industrial automation giant has fixed security holes in Logix, CompactLogix, Flex, RSLinx, and FactoryTalk products.

Vulnerabilities

The public PoC code exploits a race condition in Microsoft Defender to spawn a command prompt with System privileges.

Vulnerabilities

The flaws allow attackers to execute arbitrary PHP code and gain root privileges on shared hosting servers.

Vulnerabilities

SOCRadar has detected 30,000 compromised Fortinet firewalls that expose networks to hacking. 

Network Security

Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write.

Ransomware

Mackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version