logo

CISA flags actively exploited Office relic alongside fresh HPE flaw

ID: adc0e38d-6db8-5d58-ab38-21372add5977

STIX ID: report--adc0e38d-6db8-5d58-ab38-21372add5977

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2026-01-08

Date Updated: 2026-04-26

Author: Carly Page

...
...

CISA has added two exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2025-37164, a critical (CVSS 10.0) code-injection/RCE in HPE OneView with a public proof-of-concept and recommended hotfix, and CVE-2009-0556, an older PowerPoint code-injection flaw still being targeted on unpatched systems. The update signals active exploitation and urges rapid patching of affected environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.