logo

Hackers exploiting bug in popular Trimble Cityworks tool used by local gov’ts

ID: 7e768df0-6a27-5392-bfb3-601a7a3b7965

STIX ID: report--7e768df0-6a27-5392-bfb3-601a7a3b7965

Feed Name: The Record from Recorded Future News

Threat Score
78/100

Date Published: 2025-02-07

Date Updated: 2026-05-01

...
...

CISA and Trimble warned of CVE-2025-0994, a CVSS v4 8.4 remote code execution vulnerability in Trimble Cityworks that is being actively exploited; Trimble released a January 29 patch, provided IOCs, and federal civilian agencies were ordered to patch affected versions (prior to 15.8.9) by February 28.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.